# FileBeat - awscloudwatch input config

**URL:** <https://discuss.elastic.co/t/filebeat-awscloudwatch-input-config/259761>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [December 28, 2020, 10:07pm UTC](https://discuss.elastic.co/t/filebeat-awscloudwatch-input-config/259761 "2020-12-28T22:07:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zorkmid](https://avatars.discourse-cdn.com/v4/letter/z/e68b1a/32.png) [@Zorkmid](https://discuss.elastic.co/u/Zorkmid)\
**Post date:** [December 28, 2020, 10:07pm UTC](https://discuss.elastic.co/t/filebeat-awscloudwatch-input-config/259761/1 "2020-12-28T22:07:04Z")

</div>

Hello Everyone,

I have attempted to use the awscloudwatch input type in my FileBeat setup as follows but the appropriate ARN for the account I'm dealing with. The AWS credentials file has the correct ID keys and these are being used successfully by some python code from Jorge Bastida called AWSLOGS.

```auto
    filebeat.inputs:
    - type: awscloudwatch
      log_group_arn: arn:aws:logs:us-east-1:428152502467:log-group:test:*
      scan_frequency: 1m
      credential_profile_name: elastic-beats
      start_position: beginning

```

This is the error I'm seeing in the Filebeat event logs :  
"failed FilterLogEventsRequestEC2RoleRequestError: no EC2 instance role found"

I find this a bit odd since the AWSLOGS code uses the same access keys, role and account.

Do I have to specific the role some where as well?

Thanks  
TimW

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2021, 12:07am UTC](https://discuss.elastic.co/t/filebeat-awscloudwatch-input-config/259761/2 "2021-01-26T00:07:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
