# AWS S3 buclet with SQS failed processing SQS S3 event notification

**URL:** <https://discuss.elastic.co/t/aws-s3-buclet-with-sqs-failed-processing-sqs-s3-event-notification/350664>\
**Category:** Elastic Agent\
**Tags:** elastic-stack-security\
**Created:** [January 9, 2024, 3:06pm UTC](https://discuss.elastic.co/t/aws-s3-buclet-with-sqs-failed-processing-sqs-s3-event-notification/350664 "2024-01-09T15:06:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Merdesz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/merdesz/32/119356_2.png) [@Merdesz](https://discuss.elastic.co/u/Merdesz)\
**Post date:** [January 9, 2024, 3:06pm UTC](https://discuss.elastic.co/t/aws-s3-buclet-with-sqs-failed-processing-sqs-s3-event-notification/350664/1 "2024-01-09T15:06:58Z")

</div>

Hi!

Trying to set up the AWS Cloudtrail integration with elastic-agent/fleet.  
The integration is able to pull the SQS messages, but then it says "Failed processing SQS message.

 ![elastic-agentSQSfail2](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37bbc6a2cb5af0c2e58570a081a7e82709898551.png)  
 ![elastic-agentfail](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f8c7c581b5ecda43add7ef62c7ae1a7c4bb336fb.png)

AWS Permissions:  
 ![awsIAM](https://us1.discourse-cdn.com/elastic/original/3X/5/9/59f8ef29b710f881cf3255b3c4aa1cbbb9d91c39.png)

And it doesn't create any data streams or logs so far.  
Any idea or suggestion is welcomed.  
Thanks

---

<div class="post-metadata">

**Author:** ![tdiddy](https://avatars.discourse-cdn.com/v4/letter/t/54ee81/32.png) [@tdiddy](https://discuss.elastic.co/u/tdiddy)\
**Post date:** [January 19, 2024, 5:36pm UTC](https://discuss.elastic.co/t/aws-s3-buclet-with-sqs-failed-processing-sqs-s3-event-notification/350664/2 "2024-01-19T17:36:30Z")

</div>

Hi Merdesz, I am having the same issue.

We were able to get it work when the S3 buckets and SQS queues were in the same account. Now we are trying to access them from a different account and have this issue despite throwing every permission we can think of at it.

Are your SQS and S3 resources in the same account as the IAM principal you are using to access them from Elastic?

Thanks

---

<div class="post-metadata">

**Author:** ![Merdesz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/merdesz/32/119356_2.png) [@Merdesz](https://discuss.elastic.co/u/Merdesz)\
**Post date:** [February 2, 2024, 9:01am UTC](https://discuss.elastic.co/t/aws-s3-buclet-with-sqs-failed-processing-sqs-s3-event-notification/350664/3 "2024-02-02T09:01:54Z")

</div>

Hi tdiddy!

Turned out AWS cloud engineer did not added all of the required permissions, fixed with adding everything then turning off the un needed ones one-by-one.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2024, 9:02am UTC](https://discuss.elastic.co/t/aws-s3-buclet-with-sqs-failed-processing-sqs-s3-event-notification/350664/4 "2024-03-01T09:02:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
