Issue

I created the IAM role manually for an S3 log source in Panther, but I’m not seeing data flow. No errors are returned.

Resolution

When creating the IAM role for your S3 source, if you select to set up everything on your own, you will have to perform some additional steps after you create the IAM role. Follow the Panther documentation to finish setting up your log source: Manual IAM Role Creation - Additional Steps.

 

Cause

If S3 is not provided with the appropriate permission to work with the KMS encrypted topic, then this could be the reason that the log source cannot pull data from the S3 bucket.