# Filebeat cloudwatch input log\_group\_name\_prefix only starts one input

**URL:** <https://discuss.elastic.co/t/filebeat-cloudwatch-input-log-group-name-prefix-only-starts-one-input/289168>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 15, 2021, 8:31am UTC](https://discuss.elastic.co/t/filebeat-cloudwatch-input-log-group-name-prefix-only-starts-one-input/289168 "2021-11-15T08:31:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kkakku](https://avatars.discourse-cdn.com/v4/letter/k/ee59a6/32.png) [@Kkakku](https://discuss.elastic.co/u/Kkakku)\
**Post date:** [November 15, 2021, 8:31am UTC](https://discuss.elastic.co/t/filebeat-cloudwatch-input-log-group-name-prefix-only-starts-one-input/289168/1 "2021-11-15T08:31:47Z")

</div>

I'm trying to use aws-cloudwatch input with Filebeat 7.15.2, because I don't want to add every lambda log group separately. I've tried following input config in my filebeat.yml:

```auto

filebeat.inputs:
- type: aws-cloudwatch
  log_group_name_prefix: /aws/lambda
  region_name: eu-west-1
  role_arn: <role-arn-here>

```

However, filebeat only starts an input worker for one log group:

```auto
2021-11-15 09:55:54	
2021-11-15T07:55:54.919Z	INFO	[aws-cloudwatch]	awscloudwatch/input.go:154	aws-cloudwatch input worker for log group: '/aws/lambda/<lambda-name>' has started
2021-11-15 09:55:54	
2021-11-15T07:55:54.919Z	INFO	[crawler]	beater/crawler.go:108	Loading and starting Inputs completed. Enabled inputs: 1
		2021-11-15 09:55:54	
2021-11-15T07:55:54.919Z	INFO	[crawler]	beater/crawler.go:141	Starting input (ID: 18216316265758894950)
2021-11-15 09:55:54	
2021-11-15T07:55:54.919Z	INFO	[aws-cloudwatch]	awscloudwatch/input.go:127	Initialized AWS CloudWatch input.
2021-11-15 09:55:54	
2021-11-15T07:55:54.918Z	WARN	[cfgwarn]	awscloudwatch/input.go:81	BETA: aws-clouwatch input type is used

```

I've tried building filebeat locally and added some logging and the prefix itself works i.e. logGroupNames in the input does contain all the log groups in my account, but filebeat only starts worker for one.

According to this [Cherry-pick #26187 to 7.x: Add log\_group\_name\_prefix config option for aws-cloudwatch input by kaiyan-sheng · Pull Request #26527 · elastic/beats · GitHub](https://github.com/elastic/beats/pull/26527) my config should work, is this a bug or is there something wrong with the filebeat.yml?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2021, 10:32am UTC](https://discuss.elastic.co/t/filebeat-cloudwatch-input-log-group-name-prefix-only-starts-one-input/289168/2 "2021-12-13T10:32:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
