I created the IAM role manually for an S3 log source in Panther, but I’m not seeing data flow. No errors are returned.
When creating the IAM role for your S3 source, if you select to set up everything on your own, you will have to perform some additional steps after you create the IAM role. Follow the Panther documentation to finish setting up your log source: Manual IAM Role Creation - Additional Steps.
If S3 is not provided with the appropriate permission to work with the KMS encrypted topic, then this could be the reason that the log source cannot pull data from the S3 bucket.