# Filebeat AWS Module S3 input error queueURL is not in format

**URL:** <https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 21, 2021, 8:10pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850 "2021-01-21T20:10:49Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![cjm3625](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjm3625/32/82561_2.png) [@cjm3625](https://discuss.elastic.co/u/cjm3625)\
**Post date:** [January 21, 2021, 8:10pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/1 "2021-01-21T20:10:49Z")

</div>

Trying to use filebeat to monitor my AWS resources in ISO environment. It looks like the AWS standard endpoint is hard coded.

my filebeat.yml

```auto
filebeat.inputs:
- type: s3
  queue_url: https://sqs.us-iso-east-1.c2s.ic.gov/#####/name
  visibility_timeout: 300s

```

Errors

```auto
ERROR	[s3]	s3/input.go:93 Input 'S3' failed with: getRegionFromQueueURL failed: queueURL is not in format: https://sqs.{REGION_ENDPOINT}.amazonaws.com/{ACCOUNT_NUMBER}/{QUEUE_NAME} 

```

I am also behind a proxy and dont see the traffic hitting the proxy server, not sure if this is related.

---

<div class="post-metadata">

**Author:** ![cjm3625](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjm3625/32/82561_2.png) [@cjm3625](https://discuss.elastic.co/u/cjm3625)\
**Post date:** [February 10, 2021, 3:43pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/3 "2021-02-10T15:43:39Z")

</div>

Anything on this???

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [February 11, 2021, 9:06am UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/4 "2021-02-11T09:06:51Z")

</div>

Hi!

I think you are right. For some reason the Module expects to find the URL in this format. [beats/collector.go at 616266fa286f0ac4408348fcd4da7da2358182b1 · elastic/beats · GitHub](https://github.com/elastic/beats/blob/616266fa286f0ac4408348fcd4da7da2358182b1/x-pack/filebeat/input/awss3/collector.go#L233)

I'm not sure what would be different with your case or if it's just that the URL format is different. Most probably we just need to adjust the code so as to cover cases like yours.

@Kaiyan_Sheng do you think this would be an enhancement request?

---

<div class="post-metadata">

**Author:** ![cjm3625](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjm3625/32/82561_2.png) [@cjm3625](https://discuss.elastic.co/u/cjm3625)\
**Post date:** [February 11, 2021, 1:02pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/5 "2021-02-11T13:02:17Z")

</div>

Yeah it looks like it is hardcoded to only work if the endpoint is in AWS Commercial with .amazonaws.com as the endpoint, it looks for that in the code. we would need it to be a variable so instead of looking for say  
[https://sqs](https://sqs).{REGION\_ENDPOINT}.amazonaws.com/{ACCOUNT\_NUMBER}/{QUEUE\_NAME}  
It should be something like  
[https://sqs](https://sqs).{REGION\_ENDPOINT}.{ENDPOINT}/{ACCOUNT\_NUMBER}/{QUEUE\_NAME}  
Allowing you to set the endpoint to whatever AWS ENV you are in so in our case [c2s.ic.gov](http://c2s.ic.gov)  
This is probably also hurting the people in Gov cloud and anything else that does not point to [amazonaws.com](http://amazonaws.com)

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [March 8, 2021, 2:16am UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/6 "2021-03-08T02:16:53Z")

</div>

@cjm3625 Hey sorry I just saw the message!! Yep this looks like a bug to me! We do have `endpoint` config parameter to use but I think there is still a bug there to abstract region name from the queue URL. Do you mind creating a github issue for this please?

---

<div class="post-metadata">

**Author:** ![cjm3625](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjm3625/32/82561_2.png) [@cjm3625](https://discuss.elastic.co/u/cjm3625)\
**Post date:** [March 8, 2021, 1:23pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/7 "2021-03-08T13:23:28Z")

</div>

Sure, how do I go about doing that?

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [March 8, 2021, 2:26pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/8 "2021-03-08T14:26:10Z")

</div>

Here is the link: [https://github.com/elastic/beats/issues/new?assignees=&labels=&template=bug-report.md](https://github.com/elastic/beats/issues/new?assignees=&labels=&template=bug-report.md) Thank you!!

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [March 31, 2021, 12:10am UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/9 "2021-03-31T00:10:38Z")

</div>

Gov cloud wont be affected by this because its just different region names, but still the [amazonaws.com](http://amazonaws.com) domain. I just submitted a draft PR that i think will resolve the issue, [[Filebeat] Fix hardcoded amazonaws.com endpoint by legoguy1000 · Pull Request #24861 · elastic/beats · GitHub](https://github.com/elastic/beats/pull/24861).

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 10, 2021, 1:32pm UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/10 "2021-04-10T13:32:29Z")

</div>

The PR has been merged and will be in 7.13 and is targeted for 7.12.1 as well.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 29, 2021, 12:41am UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/11 "2021-04-29T00:41:17Z")

</div>

@cjm3625 have u been able to upgrade to 7.12.1+ to see if this solved your issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2021, 2:41am UTC](https://discuss.elastic.co/t/filebeat-aws-module-s3-input-error-queueurl-is-not-in-format/261850/12 "2021-05-27T02:41:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
