# Filebeat Cisco Umbrella module

**URL:** <https://discuss.elastic.co/t/filebeat-cisco-umbrella-module/256811>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 26, 2020, 6:13pm UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella-module/256811 "2020-11-26T18:13:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Massimo\_Brogioni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/massimo_brogioni/32/79770_2.png) [@Massimo\_Brogioni](https://discuss.elastic.co/u/Massimo_Brogioni)\
**Post date:** [November 26, 2020, 6:13pm UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella-module/256811/1 "2020-11-26T18:13:47Z")

</div>

Hi, I am trying to configure filebeat to get logs from Cisco Umbrella but something don't work.

The logs are in a bucket Cisco managed.

If I try to list the bucket I am successful, with:

`/usr/local/bin/aws s3 ls s3://umbrella-managed-<MyCompanyID>-<idKey>`

is authenticated and work flawlessy.

If I configure the umbrella filebeat module in this way:

```
          `umbrella:
            enabled: true

            var.input: s3
            # AWS SQS queue url
            var.queue_url: https://sqs.eu-south-1.amazonaws.com/2395044/
            # Access ID to authenticate with the S3 input
            var.access_key_id: <myKeyID>
            # Access key to authenticate with the S3 input
            var.secret_access_key: <mySecretAccessKey>
            # The duration that the received messages are hidden from ReceiveMessage request
            #var.visibility_timeout: 300s
            # Maximum duration before AWS API request will be interrupted
            #var.api_timeout: 120s`

```

I get a bunch of errors:

`2020-11-26T19:00:25.335+0100 ERROR [input.s3] s3/collector.go:107 SQS ReceiveMessageRequest failed: InvalidClientTokenId: The security token included in the request is invalid.`

I think I am missing the CiscoQueue, where can I find this queue ?

Thank you

---

<div class="post-metadata">

**Author:** ![C0FFEEC0FFEE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/c0ffeec0ffee/32/75111_2.png) [@C0FFEEC0FFEE](https://discuss.elastic.co/u/C0FFEEC0FFEE)\
**Post date:** [December 14, 2020, 12:30pm UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella-module/256811/2 "2020-12-14T12:30:31Z")

</div>

I stumbled upon the same problem and the only solution I came up with was to use my own S3 bucket with SQS notifications enabled. It seems to me that the buckets managed by Cisco do not have SQS notifications enabled.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2021, 2:30pm UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella-module/256811/3 "2021-01-11T14:30:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
