# aws-cloudwatch obtaining logs exception

**URL:** <https://discuss.elastic.co/t/aws-cloudwatch-obtaining-logs-exception/336401>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 19, 2023, 7:38pm UTC](https://discuss.elastic.co/t/aws-cloudwatch-obtaining-logs-exception/336401 "2023-06-19T19:38:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Askas00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/askas00/32/122455_2.png) [@Askas00](https://discuss.elastic.co/u/Askas00)\
**Post date:** [June 19, 2023, 7:38pm UTC](https://discuss.elastic.co/t/aws-cloudwatch-obtaining-logs-exception/336401/1 "2023-06-19T19:38:14Z")

</div>

When I use the aws-cloudwatch input plug-in to obtain the logs stored in cloudwatchlogs, the number of logs obtained is inconsistent with the number of logs in cloudwatchlogs. The route53 logs are stored in cloudwatchlogs. The number of logs is relatively large.  
For example, in the past two hours, there were 140W logs in cloudwatchlogs, but only 130W logs were pushed from filebeat to ES

```auto
- type: aws-cloudwatch
  log_group_arn: arn:aws:logs:ap-northeast-1:xxxxx:log-group:xxxxx:*
  scan_frequency: 30s
  start_position: end
  region_name: ap-northeast-1
  access_key_id: xxxx
  secret_access_key: xxxxx
  fields:
    env: xxx
  fields_under_root: true
  latency: 1m

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2023, 9:38pm UTC](https://discuss.elastic.co/t/aws-cloudwatch-obtaining-logs-exception/336401/2 "2023-07-17T21:38:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
