# Issue with Logstash-input-s3 for CloudTrail Global log bucket as input

**URL:** <https://discuss.elastic.co/t/issue-with-logstash-input-s3-for-cloudtrail-global-log-bucket-as-input/40931>\
**Category:** Logstash\
**Created:** [February 4, 2016, 6:35am UTC](https://discuss.elastic.co/t/issue-with-logstash-input-s3-for-cloudtrail-global-log-bucket-as-input/40931 "2016-02-04T06:35:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![apurvara](https://avatars.discourse-cdn.com/v4/letter/a/e19adc/32.png) [@apurvara](https://discuss.elastic.co/u/apurvara)\
**Post date:** [February 4, 2016, 6:35am UTC](https://discuss.elastic.co/t/issue-with-logstash-input-s3-for-cloudtrail-global-log-bucket-as-input/40931/1 "2016-02-04T06:35:45Z")

</div>

I'm trying to use LS2.1.1 with ES2.1.1 for AWS CloudTrail Log Analysis from S3 Bucket using logstash-input-s3 and logstash-codec-cloudtrail plugin.  
I am facing problem when trying to start my Logstash service where as my configuration test passed successfully.  
For debugging the problem I tried the --debug command and got the below error.

Conmmand : /opt/logstash/bin/logstash -f logstash-s3.conf –debug  
**_Part of error_**  
Settings: Default filter workers: 1  
Registering s3 input {:bucket=\>"cloudtrailbucket", :region=\>"ap-southeast-1", :level=\>:info, :file=\>"logstash/inputs/s3.rb", :line=\>"78", :method=\>"register"}  
The error reported is:  
can't convert Symbol into Integer  
org/jruby/RubyString.java:3919:in `[]=' /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-mixin-aws-2.0.2/lib/logstash/plugin_mixins/aws_config/v1.rb:40:in`aws\_options\_hash'  
/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-s3-2.0.3/lib/logstash/inputs/s3.rb:397:in `get_s3object' /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-s3-2.0.3/lib/logstash/inputs/s3.rb:80:in`register'  
/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.1.1-java/lib/logstash/pipeline.rb:165:in `start_inputs' org/jruby/RubyArray.java:1613:in`each'  
/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.1.1-java/lib/logstash/pipeline.rb:164:in `start_inputs' /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.1.1-java/lib/logstash/pipeline.rb:100:in`run'  
/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.1.1-java/lib/logstash/agent.rb:165:in `execute' /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.1.1-java/lib/logstash/runner.rb:90:in`run'  
org/jruby/RubyProc.java:281:in `call' /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.1.1-java/lib/logstash/runner.rb:95:in`run'  
org/jruby/RubyProc.java:281:in `call' /opt/logstash/vendor/bundle/jruby/1.9/gems/stud-0.0.22/lib/stud/task.rb:24:in`initialize'

* * *

My configuratoion used for logstash-input-s3:  
input {  
s3 {  
bucket =\> "cloudtrailbucket"  
delete =\> false  
interval =\> 60 # seconds  
prefix =\> "AWSLogs//CloudTrail/ "  
type =\> "cloudtrail"  
codec =\> "cloudtrail"  
region =\> "ap-southeast-1"  
aws\_credentials\_file =\> "/etc/logstash/conf.d/s3\_credentials.ini"  
sincedb\_path =\> "/opt/logstash\_cloudtrail/sincedb"  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "Client-Cloudtrail"  
}  
}  
Has anyone done this before and can share the steps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/issue-with-logstash-input-s3-for-cloudtrail-global-log-bucket-as-input/40931/2 "2017-07-06T05:13:06Z")

</div>


