# IAM permissions required for Functionbeat

**URL:** <https://discuss.elastic.co/t/iam-permissions-required-for-functionbeat/234435>\
**Category:** Beats\
**Tags:** functionbeat\
**Created:** [May 27, 2020, 12:51am UTC](https://discuss.elastic.co/t/iam-permissions-required-for-functionbeat/234435 "2020-05-27T00:51:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mudricd](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@mudricd](https://discuss.elastic.co/u/mudricd)\
**Post date:** [May 27, 2020, 12:51am UTC](https://discuss.elastic.co/t/iam-permissions-required-for-functionbeat/234435/1 "2020-05-27T00:51:16Z")

</div>

Hi,

I followed Functionbeat reference to deploy a function that collects events from CloudWatch Logs and forwards the events to Elasticsearch.

I am aware of IAM permissions required for Functionbeat deployment but I am not able to create that IAM role due to some company security restrictions. The arguable actions from recommended role are:

```auto
iam:CreateRole
iam:DeleteRole
iam:DeleteRolePolicy

```

My cloud team advise to investigate what those roles are that Functionbeat needs to create and delete and then to set up that permissions over our internal "IAM manager".

Could you please advise if this is doable?

Cheers,  
Dragan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2020, 2:51pm UTC](https://discuss.elastic.co/t/iam-permissions-required-for-functionbeat/234435/2 "2020-06-16T14:51:20Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
