# Elastic forwarder cloudwatch log group wildcard id not working

**URL:** <https://discuss.elastic.co/t/elastic-forwarder-cloudwatch-log-group-wildcard-id-not-working/329987>\
**Category:** Beats\
**Tags:** functionbeat\
**Created:** [April 14, 2023, 9:35am UTC](https://discuss.elastic.co/t/elastic-forwarder-cloudwatch-log-group-wildcard-id-not-working/329987 "2023-04-14T09:35:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dchocoboo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dchocoboo/32/119819_2.png) [@dchocoboo](https://discuss.elastic.co/u/dchocoboo)\
**Post date:** [April 14, 2023, 9:35am UTC](https://discuss.elastic.co/t/elastic-forwarder-cloudwatch-log-group-wildcard-id-not-working/329987/1 "2023-04-14T09:35:01Z")

</div>

i'm trying to simplify my config.yaml based on this tutorial

> **[Deploy Elastic Serverless Forwarder | Observability Guide \[master\] | Elastic](https://www.elastic.co/guide/en/observability/master/aws-deploy-elastic-serverless-forwarder.html)**
>
> Deploy the Elastic Serverless Forwarder using Kibana and the AWS Serverless Application Repository (SAR).

currently if i put this in my config

```auto
- type: "cloudwatch-logs"
    id: "arn:aws:logs:ap-southeast-1:xxxxxxxxxx:log-group:*:*"
    outputs:
      - type: "elasticsearch"
        args:
          cloud_id: "${elastic_cloud_id}"
          api_key: "${elastic_api_key}"
          es_datastream_name: "logs-generic-default"
          batch_max_actions: 500 # optional: default value is 500
          batch_max_bytes: 10485760 # optional: default value is 10485760

```

the lambda is giving this error

```auto
{
    "@timestamp": "2023-04-11T06:02:03.794Z",
    "log.level": "warning",
    "message": "no input defined",
    "ecs": {
        "version": "1.6.0"
    },
    "input_id": "",
    "input_type": "cloudwatch-logs",
    "log": {
        "logger": "root",
        "origin": {
            "file": {
                "line": 146,
                "name": "handler.py"
            },
            "function": "lambda_handler"
        },
        "original": "no input defined"
    },
    "process": {
        "name": "MainProcess",
        "pid": 8,
        "thread": {
            "id": 140499231172416,
            "name": "MainThread"
        }
    }
}

```

however the config below works well.

```auto
- type: "cloudwatch-logs"
    id: "arn:aws:logs:ap-southeast-1:xxxxxxxxxx:log-group:myloggroup:*"
    outputs:
      - type: "elasticsearch"
        args:
          cloud_id: "${elastic_cloud_id}"
          api_key: "${elastic_api_key}"
          es_datastream_name: "logs-generic-default"
          batch_max_actions: 500 # optional: default value is 500
          batch_max_bytes: 10485760 # optional: default value is 10485760

```

is there anyway i can use wildcard for specifying log groups,  
the outputs for each entry are all the same so i really don't see the point of repeating blocks of config for every log group ... as i have hundreds of them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2023, 11:35am UTC](https://discuss.elastic.co/t/elastic-forwarder-cloudwatch-log-group-wildcard-id-not-working/329987/2 "2023-05-12T11:35:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
