# ERROR - Cloudwatch Output plugin - Direct event field references have been disabled

**URL:** <https://discuss.elastic.co/t/error-cloudwatch-output-plugin-direct-event-field-references-have-been-disabled/71231>\
**Category:** Logstash\
**Created:** [January 11, 2017, 2:19pm UTC](https://discuss.elastic.co/t/error-cloudwatch-output-plugin-direct-event-field-references-have-been-disabled/71231 "2017-01-11T14:19:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![CliveL](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clivel/32/14468_2.png) [@CliveL](https://discuss.elastic.co/u/CliveL)\
**Post date:** [January 11, 2017, 2:19pm UTC](https://discuss.elastic.co/t/error-cloudwatch-output-plugin-direct-event-field-references-have-been-disabled/71231/1 "2017-01-11T14:19:17Z")

</div>

Hi,

I have been trying to use the Cloudwatch Output plugin in both Logstash 5.0.1 and 5.1.1 and when I set the Cloudwatch Output to DEBUG I see the following lines when it attempts to set a metric:

> [2017-01-11T12:41:21,953][DEBUG][logstash.outputs.cloudwatch] Queueing event {:event=\>2017-01-11T12:41:19.333Z msggw-api-1 %{message}}  
> [2017-01-11T12:41:23,871][DEBUG][logstash.outputs.cloudwatch] Scheduler Activated  
> [2017-01-11T12:41:23,872][DEBUG][logstash.outputs.cloudwatch] QUEUE SIZE {:queuesize=\>1}  
> [2017-01-11T12:41:23,873][WARN][logstash.outputs.cloudwatch] Exception! Breaking count loop {:exception=\># NoMethodError: Direct event field references (i.e. event['field']) have been disabled in favor of using event get and set methods (e.g. event.get('field')). Please consult the Logstash 5.0 breaking changes documentation for more details.\>}

I think this is related to using a "nested field" as the source of the metric value, although when I use a top-level field I still get the same error in the logs, so this may just be a version incompatibility? I have checked that I am running the latest update of the plugin in both LS 5.0.1 and 5.1.1.

I have set the CW\_dimensions, CW\_namespace and CW\_metricname fields using the Mutate filter. I am trying to set the Value field in the Cloudwatch Output filter config as follows:

field\_value =\> "[@fields][resp\_time][value]"

This is the nested location of the field containing the number type that I wanted to be injected into a custom Cloudwatch metric.

Is anyone able to confirm if this is bug in the plugin, or my config?

Many thanks!

---

<div class="post-metadata">

**Author:** ![CliveL](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clivel/32/14468_2.png) [@CliveL](https://discuss.elastic.co/u/CliveL)\
**Post date:** [January 13, 2017, 4:02pm UTC](https://discuss.elastic.co/t/error-cloudwatch-output-plugin-direct-event-field-references-have-been-disabled/71231/2 "2017-01-13T16:02:24Z")

</div>

I've looked further into this issue today and modified the plugin Ruby file to be compatible with the new Event API changes that were introduced in Logstash 5.0. My fork of the plugin is now working and I've issued a Pull Request for the project. I'll close this issue here...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2017, 4:03pm UTC](https://discuss.elastic.co/t/error-cloudwatch-output-plugin-direct-event-field-references-have-been-disabled/71231/3 "2017-02-10T16:03:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
