# Fleet AWS Cloudtrail integration stops working after upgrading elastic agent to 7.12.0

**URL:** <https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120>\
**Category:** Beats\
**Tags:** elastic-agent\
**Created:** [April 2, 2021, 4:09pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120 "2021-04-02T16:09:31Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Post date:** [April 2, 2021, 4:09pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/1 "2021-04-02T16:09:31Z")

</div>

Hi all,

We have a working AWS CloudTrail integration with Elastic agent 7.10.1. After upgrading to 7.12 the cloud trail data stops working without any error in the log.

I have tried to enabled debug level on agent but there is no error message at all.

Any idea how to solve the issue or at least to know what the error is?

Thank you.

Regards,  
Nugroho

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [April 6, 2021, 3:44pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/2 "2021-04-06T15:44:19Z")

</div>

Hmmm have you tried 7.11? There is a bug introduced into 7.12 and it's fixed by [[Filebeat] Fix gcp/vpcflow module defaulting to file input by andrewkroh · Pull Request #24719 · elastic/beats · GitHub](https://github.com/elastic/beats/pull/24719).

---

<div class="post-metadata">

**Author:** ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Post date:** [April 6, 2021, 5:01pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/3 "2021-04-06T17:01:25Z")

</div>

@Kaiyan_Sheng I don't think that fix is related to the issue that I have (GCP vs AWS).

---

<div class="post-metadata">

**Author:** ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Post date:** [April 6, 2021, 6:27pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/4 "2021-04-06T18:27:21Z")

</div>

@Kaiyan_Sheng I can confirm that it works after I rolled back to 7.11.2.

I use IAM Instance Profile (associated with IAM Role) attached to EC2 and set all configuration to blank (no access key, no credentials, no role) and it works (default SDK fallback behavior-- good).

It seems 7.12 breaks that behavior.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/957f181e4859a4de4283eb8a975b488590f2e091.png)

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [April 7, 2021, 2:15pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/5 "2021-04-07T14:15:42Z")

</div>

Thank you @nugroho-expereo for confirming!! OK I will go investigate what changed here!! Thanks!!

---

<div class="post-metadata">

**Author:** ![kspalding](https://avatars.discourse-cdn.com/v4/letter/k/a9adbd/32.png) [@kspalding](https://discuss.elastic.co/u/kspalding)\
**Post date:** [April 10, 2021, 12:17am UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/6 "2021-04-10T00:17:18Z")

</div>

> [@Kaiyan\_Sheng](#):
>
> [Filebeat] Fix gcp/vpcflow module defaulting to file input by andrewkroh · Pull Request #24719 · elastic/beats · GitHub

I have also found this to be the case. Today I upgraded our ES from 7.11 to 7.12, as well as upgrading my Elastic Agent to 7.12 after which I am no longer receiving logs using the AWS Integration. Prior 7.11 was working fine.

Also note that I am collecting AWS CloudTrail and VPCFlow which which have both stoped. In an effort to try to fix I deployed a newer version of the integration from AWS v0.3.12 to AWS v0.5.0 which did not seem to fix the problem. Unlike Nugroho I am not using EC2 with IAM Role, I am using Access ID\Key.

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [April 28, 2021, 9:25pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/7 "2021-04-28T21:25:57Z")

</div>

Hello! Sorry for the late response here. I did some testing and found AWS log integration is broken because of the renaming of s3 input to aws-s3 input. Here is the PR that should fix this: [Change s3 input name to aws-s3 by kaiyan-sheng · Pull Request #631 · elastic/integrations · GitHub](https://github.com/elastic/integrations/pull/631)

---

<div class="post-metadata">

**Author:** ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Post date:** [April 29, 2021, 12:26pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/8 "2021-04-29T12:26:26Z")

</div>

Thank you @Kaiyan_Sheng. When will the fix be released?

---

<div class="post-metadata">

**Author:** ![kspalding](https://avatars.discourse-cdn.com/v4/letter/k/a9adbd/32.png) [@kspalding](https://discuss.elastic.co/u/kspalding)\
**Post date:** [May 4, 2021, 6:20pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/9 "2021-05-04T18:20:37Z")

</div>

Hi @Kaiyan_Sheng

I see 7.12.1 was released a few days ago. Is the fix related to the s3 input naming (Pull Request 631) included with included with 7.12.1 release?

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [May 19, 2021, 9:28pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/10 "2021-05-19T21:28:52Z")

</div>

Hello! This change is only affecting the aws integration and it is released in 0.5.4.

---

<div class="post-metadata">

**Author:** ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)\
**Post date:** [May 31, 2021, 12:05pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/11 "2021-05-31T12:05:22Z")

</div>

Thank you @Kaiyan_Sheng. It works after upgrading to 7.13 and the latest AWS package.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2021, 2:06pm UTC](https://discuss.elastic.co/t/fleet-aws-cloudtrail-integration-stops-working-after-upgrading-elastic-agent-to-7-12-0/269120/12 "2021-06-28T14:06:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
