# AWS clouldtrail user activity logs to elasticcloud

**URL:** <https://discuss.elastic.co/t/aws-clouldtrail-user-activity-logs-to-elasticcloud/355198>\
**Category:** Elasticsearch\
**Created:** [March 12, 2024, 12:15am UTC](https://discuss.elastic.co/t/aws-clouldtrail-user-activity-logs-to-elasticcloud/355198 "2024-03-12T00:15:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![joshuskarki](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@joshuskarki](https://discuss.elastic.co/u/joshuskarki)\
**Post date:** [March 12, 2024, 12:15am UTC](https://discuss.elastic.co/t/aws-clouldtrail-user-activity-logs-to-elasticcloud/355198/1 "2024-03-12T00:15:49Z")

</div>

Has anyone here successfully ingested AWS CloudTrail user activity logs into Elastic using CloudTrail integration and pulled data from SQS (CloudTrail -\> S3 -\> SQS with SNS enabled)?

I am specifically wondering about the permissions I need for IAM, S3, and SQS to enable an unrestricted log flow to Elastic.

Thanks for any useful pointers.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 12, 2024, 2:00am UTC](https://discuss.elastic.co/t/aws-clouldtrail-user-activity-logs-to-elasticcloud/355198/2 "2024-03-12T02:00:34Z")

</div>

I do not use the integration as I collect the Cloudtrail logs on a different way, but the permissions needed are listed here, in this [part of the documentation](https://docs.elastic.co/integrations/aws#aws-permissions).

---

<div class="post-metadata">

**Author:** ![joshuskarki](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@joshuskarki](https://discuss.elastic.co/u/joshuskarki)\
**Post date:** [March 12, 2024, 7:25pm UTC](https://discuss.elastic.co/t/aws-clouldtrail-user-activity-logs-to-elasticcloud/355198/3 "2024-03-12T19:25:16Z")

</div>

Thanks @leandrojmp  
I believe the IAM permissions are configured correctly. However, I'm encountering an issue with creating an S3 event notification to SQS. The error message states: '_The user likely does not have the necessary permissions to configure notifications for this S3 bucket. While the bucket itself may allow listing and accessing objects, permission to modify bucket properties and notifications is controlled separately._'  
It's unusual to encounter this error, especially considering that I am the admin with root access to the AWS console. I've double-checked the permissions, and I believe I've correctly granted the necessary permissions for S3 to interact with SQS, as documented below.

> **[Granting permissions to publish event notification messages to a destination...](https://docs.aws.amazon.com/AmazonS3/latest/userguide/grant-destinations-permissions-to-s3.html#grant-sns-sqs-permission-for-s3)**
>
> Grant the Amazon S3 principal the necessary permissions to call the relevant API to publish event notification messages to an SNS topic, an SQS queue, or a Lambda function.

---

<div class="post-metadata">

**Author:** ![joshuskarki](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@joshuskarki](https://discuss.elastic.co/u/joshuskarki)\
**Post date:** [March 12, 2024, 11:13pm UTC](https://discuss.elastic.co/t/aws-clouldtrail-user-activity-logs-to-elasticcloud/355198/4 "2024-03-12T23:13:29Z")

</div>

The error disappeared after providing the correct account ID for the permissions on SNS and SQS.

```
            "StringEquals": {
                "aws:SourceAccount": "bucket-owner-account-id"

```

The agent is now successfully receiving logs for SQS. However, the default integrated dashboard provided by Kibana is somewhat annoying and partially broken. I'm unable to modify it, but since there's that raw data, I can manage it differently.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2024, 11:13pm UTC](https://discuss.elastic.co/t/aws-clouldtrail-user-activity-logs-to-elasticcloud/355198/5 "2024-04-09T23:13:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
