I was attempting to upgrade filebeat to the latest release from 7.9.0, but am unable to get any version past 7.9.1 to work.
Starting with 7.9.2, debug shows filebeat receiving the SQS message, but it doesn't return any "s3 log info". It then deletes the sqs message.
2021-01-16T00:05:08.828Z DEBUG [s3] s3/input.go:241 Processing 3 messages
2021-01-16T00:05:08.828Z DEBUG [s3] s3/input.go:261 handleSQSMessage succeed and returned 0 sets of S3 log info
2021-01-16T00:05:08.828Z DEBUG [s3] s3/input.go:261 handleSQSMessage succeed and returned 0 sets of S3 log info
2021-01-16T00:05:08.828Z DEBUG [s3] s3/input.go:261 handleSQSMessage succeed and returned 0 sets of S3 log info
2021-01-16T00:05:08.828Z DEBUG [s3] s3/input.go:270 handleS3Objects succeed
2021-01-16T00:05:08.828Z DEBUG [s3] s3/input.go:270 handleS3Objects succeed
2021-01-16T00:05:08.828Z DEBUG [s3] s3/input.go:291 Deleting message from SQS: 0xc0002d6e00
2021-01-16T00:05:08.828Z DEBUG [s3] s3/input.go:291 Deleting message from SQS: 0xc0002d6e00
2021-01-16T00:05:08.828Z DEBUG [s3] s3/input.go:291 Deleting message from SQS: 0xc0002d6fb0
2021-01-16T00:05:08.828Z DEBUG [s3] s3/input.go:291 Deleting message from SQS: 0xc0002d6ef0
With 7.9.1, it properly breaks down the message and publishes the event
2021-01-16T00:14:30.424Z DEBUG [processors] processing/processors.go:187 Publish event: {
"@timestamp": "2021-01-16T00:14:30.424Z",
"@metadata": {
"beat": "filebeat",
"type": "_doc",
"version": "7.9.1",
"_id": "4d35b4e3d4-000000017417",
"pipeline": "filebeat-7.9.1-aws-cloudtrail-pipeline"
},