# Logstash cloudwatch plugin error

**URL:** <https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error/254337>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [November 4, 2020, 10:58pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error/254337 "2020-11-04T22:58:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![deep9300](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@deep9300](https://discuss.elastic.co/u/deep9300)\
**Post date:** [November 4, 2020, 10:58pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error/254337/1 "2020-11-04T22:58:16Z")

</div>

I'm trying to connect cloudwatch to logstash but get an error.

this is my logstash conf file:

```auto
input {
      cloudwatch {
        namespace => "AWS/Transfer"
        metrics => ["BytesIn", "BytesOut"]
        filters => { "tag:Monitoring" => "YES" }
        region => "us-east-1"
      }
    }

output {
        elasticsearch {
                hosts => ["10.50.73.138:9200", "10.50.73.139:9200", "10.50.73.140:9200"]
                index => "s3-logs-%{+YYYY.MM.dd}"
        }
}

```

Getting this error:

```auto
2020-11-04T16:59:10,864][INFO][logstash.inputs.cloudwatch][main] Polling CloudWatch API
[2020-11-04T16:59:10,867][ERROR][logstash.javapipeline][main] A plugin had an unrecoverable error. Will restart this plugin.
  Pipeline_id:main
  Plugin: <LogStash::Inputs::CloudWatch namespace=>"AWS/Transfer", metrics=>["BytesIn", "BytesOut"], filters=>{"tag:Monitoring"=>"YES"}, id=>"595c3d5fea339cb6cae4076c012b260091ac12c24ce9ec69b13755277602c4b7", region=>"us-east-1", enable_metric=>true, codec=><LogStash::Codecs::Plain id=>"plain_652be412-8523-4365-abba-5780a269558f", enable_metric=>true, charset=>"UTF-8">, role_session_name=>"logstash", statistics=>["SampleCount", "Average", "Minimum", "Maximum", "Sum"], interval=>900, period=>300, combined=>false>
  Error: No metrics to query
  Exception: RuntimeError
  Stack: /usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-cloudwatch-2.2.4/lib/logstash/inputs/cloudwatch.rb:154:in `run'
/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:328:in `inputworker'
/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:320:in `block in start_input'

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 4, 2020, 11:35pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error/254337/2 "2020-11-04T23:35:15Z")

</div>

> [@deep9300](#):
>
> `Error: No metrics to query`

The input has decided that the set of metrics it can collect is empty. Are you sure you want that filters option?

---

<div class="post-metadata">

**Author:** ![deep9300](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@deep9300](https://discuss.elastic.co/u/deep9300)\
**Post date:** [November 5, 2020, 6:04pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error/254337/3 "2020-11-05T18:04:11Z")

</div>

Filters must be defined for when using AWS/Transfer namespace

I tried to remove the filters part but looks like I would need some sort of filter.

I want filters like:

filter @message like "READ"  
| fields @timestamp  
| sort @timestamp desc  
| stats count(\*) as FileRead by bin(10min)

filter @message like "ERROR"  
| fields @timestamp  
| sort @timestamp desc  
| stats count(\*) as Errors by bin(24hr)

filter @message like "OPEN"  
| parse @message "_._ OPEN Path=\* Mode=\*" as user, sessionID, path, mode  
| fields @timestamp  
| sort @timestamp desc  
| stats count\_distinct(sessionID) as uniquesessions by bin(10min)

filter @message like "OPEN"  
| parse @message "_._ OPEN Path=\* Mode=\*" as user, sessionID, path, mode  
| fields @timestamp  
| filter mode like "READ"  
| sort path desc  
| stats count(path) as NumberOfRequests by path  
| limit 10

How would I add this in the conf file?

---

<div class="post-metadata">

**Author:** ![deep9300](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@deep9300](https://discuss.elastic.co/u/deep9300)\
**Post date:** [November 5, 2020, 8:54pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error/254337/4 "2020-11-05T20:54:52Z")

</div>

this is in reference to

> **[Monitoring your AWS SFTP Environment | Amazon Web Services](https://aws.amazon.com/blogs/storage/monitoring-your-aws-sftp-environment/)**
>
> Organizations across the board use the Secure File Transfer Protocol (SFTP), also known as the Secure Shell (SSH) File Transfer Protocol, to share files for their business needs. SFTP is a well-established protocol that allows for easy and secure...

go down to "Widget Connected users"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2020, 8:55pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error/254337/5 "2020-12-03T20:55:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
