# Filebeat Cisco Umbrella

**URL:** <https://discuss.elastic.co/t/filebeat-cisco-umbrella/258779>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 15, 2020, 9:10pm UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella/258779 "2020-12-15T21:10:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nathanachey](https://avatars.discourse-cdn.com/v4/letter/n/ce7236/32.png) [@nathanachey](https://discuss.elastic.co/u/nathanachey)\
**Post date:** [December 15, 2020, 9:10pm UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella/258779/1 "2020-12-15T21:10:03Z")

</div>

I'm trying to setup Filebeat to use the Cisco Umbrella module. We have the Cisco maintained bucket. The URL Cisco provides is `s3://cisco-managed-us-west-1/2613934_1b0f4f029c8f0b75a2f9a6d4e06a79d6cbbc41bb`

The error I'm getting is

`"ERROR [input.s3] s3/input.go:93 getRegionFromQueueURL failed: queueURL is not in format: https://sqs.{REGION_ENDPOINT}.amazonaws.com/{ACCOUNT_NUMBER}/{QUEUE_NAME} {"queue_url": "s3://cisco-managed-us-west-1/2613934_1b0f4f029c8f0b75a2f9a6d4e06a79d6cbbc41bb"}"`

My module config is

> ```
> umbrella:
> enabled: true
> var.input: s3
> # AWS SQS queue url
> var.queue_url: s3://cisco-managed-us-west-1/2613934_1b0f4f029c8f0b75a2f9a6d4e06a79d6cbbc41bb
> # Access ID to authenticate with the S3 input
> var.access_key_id: <mykey>
> # Access key to authenticate with the S3 input
> var.secret_access_key: <mypass>
> # The duration that the received messages are hidden from ReceiveMessage request
> #var.visibility_timeout: 300s
> # Maximum duration before AWS API request will be interrupted
> #var.api_timeout: 120s
> 
> ```

The Cisco module documentation says that you can use the Cisco managed bucket, but I'm just not sure of the format of the var.queue\_url. Does anyone know the trick?

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [December 16, 2020, 1:19am UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella/258779/2 "2020-12-16T01:19:55Z")

</div>

Hello! You would need to set up an SQS for notification when there's new logs send into S3. Please see [https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-input-s3.html#\_s3\_and\_sqs\_setup](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-input-s3.html#_s3_and_sqs_setup) for more info. Thanks!

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [December 17, 2020, 1:32pm UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella/258779/3 "2020-12-17T13:32:12Z")

</div>

Hi @nathanachey! Unfortunately we do not support Cisco-managed S3 buckets at this time and have updated our [docs](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-cisco.html) accordingly. Cisco-managed buckets do not leverage SQS notifications, but Filebeat's S3 input relies on SQS. We are exploring possible solutions with a view to supporting Cisco-managed buckets in the future.

---

<div class="post-metadata">

**Author:** ![nathanachey](https://avatars.discourse-cdn.com/v4/letter/n/ce7236/32.png) [@nathanachey](https://discuss.elastic.co/u/nathanachey)\
**Post date:** [December 17, 2020, 2:01pm UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella/258779/4 "2020-12-17T14:01:26Z")

</div>

OK

Thanks for the clarification. I will look into get our own S3 bucket.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2021, 4:01pm UTC](https://discuss.elastic.co/t/filebeat-cisco-umbrella/258779/5 "2021-01-14T16:01:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
