# Filebeat using IAM role for ECS tasks does not work

**URL:** <https://discuss.elastic.co/t/filebeat-using-iam-role-for-ecs-tasks-does-not-work/308851>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 5, 2022, 4:30am UTC](https://discuss.elastic.co/t/filebeat-using-iam-role-for-ecs-tasks-does-not-work/308851 "2022-07-05T04:30:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![masato](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@masato](https://discuss.elastic.co/u/masato)\
**Post date:** [July 5, 2022, 4:30am UTC](https://discuss.elastic.co/t/filebeat-using-iam-role-for-ecs-tasks-does-not-work/308851/1 "2022-07-05T04:30:49Z")

</div>

Hi team,

I've tried to run filebeat with the cisco module (umbrella) in the ECS task. The umbrella module is configured without access\_key\_id and secret\_access\_key. I think I can now achieve filebeat using the IAM role for ECS task, but it doesn't work. please let me know if I can use filebeat with the ECS task role?

umbrella module setting

```auto
- module: cisco
  umbrella:
    enabled: true
    var.input: aws-s3
    var.queue_url: ${SQS_URL:?SQS_URL is empty}

```

log

```auto
2022-07-05T02:14:14.372Z ERROR [input.aws-s3] awss3/collector.go:106 SQS ReceiveMessageRequest failed: IncompleteSignature: 'value>/20220705/ap-northeast-1/sqs/aws4_request' not a valid key=value pair (missing equal-sign) in Authorization header: 'AWS4-HMAC-SHA256 Credential=<no value>/20220705/ap-northeast-1/sqs/aws4_request, SignedHeaders=content-length;content-type;host;x-amz-date, Signature=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX'.

```

filebeat version: 7.14.2

[AWS ECS IAM roles for tasks](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task-iam-roles.html)

[Perhaps this topic is related to my question.](https://discuss.elastic.co/t/filebeat-aws-s3-module-not-working/268781/6)

---

<div class="post-metadata">

**Author:** ![masato](https://avatars.discourse-cdn.com/v4/letter/m/b5a626/32.png) [@masato](https://discuss.elastic.co/u/masato)\
**Post date:** [July 8, 2022, 5:01am UTC](https://discuss.elastic.co/t/filebeat-using-iam-role-for-ecs-tasks-does-not-work/308851/2 "2022-07-08T05:01:30Z")

</div>

So far, the cisco module (umbrella) does not seem to support the ECS task role. We can workaround this by removing or commenting out the lines(access\_key\_id, secret\_access\_key) in the input.yml of this module. But this is not a recommended.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2022, 7:01am UTC](https://discuss.elastic.co/t/filebeat-using-iam-role-for-ecs-tasks-does-not-work/308851/3 "2022-08-05T07:01:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
