# Cloudwatch log group stream using logstash to ES

**URL:** <https://discuss.elastic.co/t/cloudwatch-log-group-stream-using-logstash-to-es/281378>\
**Category:** Logstash\
**Created:** [August 13, 2021, 3:24pm UTC](https://discuss.elastic.co/t/cloudwatch-log-group-stream-using-logstash-to-es/281378 "2021-08-13T15:24:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![connectgeeks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/connectgeeks/32/90595_2.png) [@connectgeeks](https://discuss.elastic.co/u/connectgeeks)\
**Post date:** [August 13, 2021, 3:24pm UTC](https://discuss.elastic.co/t/cloudwatch-log-group-stream-using-logstash-to-es/281378/1 "2021-08-13T15:24:42Z")

</div>

Hi

I'm using logstash-7.14.0-1.x86\_64 version and would like to stream cloudwatch loggroup to ES. When I'm trying to use plugin `bin/logstash-plugin install logstash-input-cloudwatch` it doesn't seems to work for log group.

```auto
[2021-08-13T15:00:49,553][ERROR][logstash.inputs.cloudwatch] Unknown setting 'log_group' for cloudwatch
[2021-08-13T15:00:49,555][ERROR][logstash.inputs.cloudwatch] Unknown setting 'log_group_prefix' for cloudwatch
[2021-08-13T15:00:49,562][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:sample, :exception=>"Java::JavaLang::IllegalStateException", :message=>"Unable to configure plugins: (ConfigurationError) Something is wrong with your configuration.", :backtrace=>["org.logstash.config.ir.CompiledPipeline.<init>(CompiledPipeline.java:119)", "org.logstash.execution.JavaBasePipelineExt.initialize(JavaBasePipelineExt.java:86)", "org.logstash.execution.JavaBasePipelineExt$INVOKER$i$1$0$initialize.call(JavaBasePipelineExt$INVOKER$i$1$0$initialize.gen)", "org.jruby.internal.runtime.methods.JavaMethod$JavaMethodN.call(JavaMethod.java:837)", "org.jruby.ir.runtime.IRRuntimeHelpers.instanceSuper(IRRuntimeHelpers.java:1169)", "org.jruby.ir.instructions.InstanceSuperInstr.interpret(InstanceSuperInstr.java:84)", "org.jruby.ir.interpreter.InterpreterEngine.processCall(InterpreterEngine.java:361)", "org.jruby.ir.interpreter.StartupInterpreterEngine.interpret(StartupInterpreterEngine.java:72)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.INTERPRET_METHOD(MixedModeIRMethod.java:86)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:73)", "org.jruby.runtime.callsite.CachingCallSite.call(CachingCallSite.java:85)", "org.jruby.RubyClass.newInstance(RubyClass.java:939)", "org.jruby.RubyClass$INVOKER$i$newInstance.call(RubyClass$INVOKER$i$newInstance.gen)", "org.jruby.runtime.callsite.CachingCallSite.call(CachingCallSite.java:85)", "org.jruby.ir.instructions.CallBase.interpret(CallBase.java:549)", "org.jruby.ir.interpreter.InterpreterEngine.processCall(InterpreterEngine.java:361)", "org.jruby.ir.interpreter.StartupInterpreterEngine.interpret(StartupInterpreterEngine.java:72)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.INTERPRET_METHOD(MixedModeIRMethod.java:86)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:73)", "org.jruby.ir.targets.InvokeSite.invoke(InvokeSite.java:207)", "usr.share.logstash.logstash_minus_core.lib.logstash.agent.RUBY$block$converge_state$2(/usr/share/logstash/logstash-core/lib/logstash/agent.rb:391)", "org.jruby.runtime.CompiledIRBlockBody.callDirect(CompiledIRBlockBody.java:138)", "org.jruby.runtime.IRBlockBody.call(IRBlockBody.java:58)", "org.jruby.runtime.IRBlockBody.call(IRBlockBody.java:52)", "org.jruby.runtime.Block.call(Block.java:139)", "org.jruby.RubyProc.call(RubyProc.java:318)", "org.jruby.internal.runtime.RubyRunnable.run(RubyRunnable.java:105)", "java.base/java.lang.Thread.run(Thread.java:829)"]}
[2021-08-13T15:00:49,568][ERROR][logstash.agent] An exception happened when converging configuration {:exception=>LogStash::Error, :message=>"Don't know how to handle `Java::JavaLang::IllegalStateException` for `PipelineAction::Create<sample>`"}

```

My configuration looks like

```auto
input{
  cloudwatch {
    log_group_prefix => true
    log_group => ["/ec2/custom/new"]
    region => "ap-xxxx-x"
  }
}
filter {
  json {
    source => "message"
  }
  mutate {
    add_field => { "read_timestamp" => "%{@timestamp}" }
  }
}
output {
  stdout {
    codec => rubydebug
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 13, 2021, 3:27pm UTC](https://discuss.elastic.co/t/cloudwatch-log-group-stream-using-logstash-to-es/281378/2 "2021-08-13T15:27:29Z")

</div>

You appear to be confusing the [cloudwatch](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-cloudwatch.html) input with the [cloudwatch\_logs](https://github.com/lukewaite/logstash-input-cloudwatch-logs) input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2021, 3:28pm UTC](https://discuss.elastic.co/t/cloudwatch-log-group-stream-using-logstash-to-es/281378/3 "2021-09-10T15:28:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
