Lake formation Database resource link is not showing in QuickSight

258 views Asked by At

I need some help accessing the lake formation database resource link in QuickSight.

Here's the scenario,

In My Source Account (Account A), I have databases and tables in the lake formation data catalog. The S3 bucket, where all findings are stored from security hub, is also in Account A. I have shared these resources with my another AWS account which is Target Account(Account B). In Account B, I created a database resource link, and I can access the database and tables in Athena and query them. However, I am not seeing my database and tables in QuickSight Dataset. I also followed the steps in below link provided by QuickSight Experts but still not working.

https://community.amazonquicksight.com/t/can-a-cross-account-lake-formation-resource-be-used-in-quicksight/1302

https://community.amazonquicksight.com/t/security-lake-athena-db-not-visible-for-dataset-selection/8358/4

I have also asked the same question to aws re:post. https://repost.aws/questions/QUJRD6TuH5RJOt1RSNWMqMJQ#AN7WcMKkvLRPOOyeSvBiCMJQ

If anyone has encountered the same issue or any idea, please share with me and help me to figure out this. Thank you.

Things i've tried,

  1. I tried creating data source again in QuickSight, didn't work.
  2. In QuickSight security & permissions, I have granted S3 and Athena services and selected data source (bucket) as an [S3 bucket you can access across AWS].I have checked the QuickSight Role which is "aws-quicksight-service-role-v0" and it has necessary S3 bucket permissions such as s3:GetObject, s3:ListBucket permissions.
  3. My target account is using OrganizationAccountAccessRole with a full admin access, and i have given the permission to access the lake formation to it (AWSLakeFormationDataAdmin). I have also given it AthenaFullAccess.
  4. In database resource link of Target Account, I granted permission to QuickSight ARN but when i select the database link and view permission, the grant is not sticking and it's empty. However permission are showing in Data lake permission pane.
0

There are 0 answers