# Logstash S3 input plugin doesn't work

**URL:** <https://discuss.elastic.co/t/logstash-s3-input-plugin-doesnt-work/48298>\
**Category:** Logstash\
**Created:** [April 25, 2016, 10:01am UTC](https://discuss.elastic.co/t/logstash-s3-input-plugin-doesnt-work/48298 "2016-04-25T10:01:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tuxknight](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuxknight/32/34457_2.png) [@tuxknight](https://discuss.elastic.co/u/tuxknight)\
**Post date:** [April 25, 2016, 10:01am UTC](https://discuss.elastic.co/t/logstash-s3-input-plugin-doesnt-work/48298/1 "2016-04-25T10:01:43Z")

</div>

This is what I got in logstash.log

> 

{:timestamp=\>"2016-04-25T17:26:13.863000+0800", :message=\>"A plugin had an unrecoverable error. Will restart this plugin.\n Plugin: \<LogStash::Inputs::S3 bucket=\>"xxx-elb-log", access\_key\_id=\>"xxxxxxxx", secret\_access\_key=\>"xxxxxx", interval=\>300, prefix=\>"xxx/AWSLogs", region=\>"cn-north-1", tags=\>["xxx", "elb"], type=\>"xxx", use\_ssl=\>true, codec=\>\<LogStash::Codecs::Plain charset=\>"UTF-8"\>, delete=\>false, temporary\_directory=\>"/var/lib/logstash/logstash"\>\n Error: initialize: name or service not known", :level=\>:error}

Here is the configuration about s3 input

> 

input {  
s3 {  
bucket =\> "xxx-elb-log"  
access\_key\_id =\> "xxxxxxx"  
secret\_access\_key =\> "xxxxxx"  
interval =\> 300  
prefix =\> "xxx/AWSLogs"  
region =\> "cn-north-1"  
tags =\> ["xxx","elb"]  
type =\> "xxx"  
use\_ssl =\> true  
}  
}

I installed logstash using _logstash-all-plugins-2.3.1.tar.gz_

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 25, 2016, 8:03pm UTC](https://discuss.elastic.co/t/logstash-s3-input-plugin-doesnt-work/48298/2 "2016-04-25T20:03:56Z")

</div>

The "name or service not known" error message typically means a DNS lookup issue. The GitHub issue below seems to describe the problem and contains a workaround.

> <https://github.com/logstash-plugins/logstash-output-s3/issues/72>

---

<div class="post-metadata">

**Author:** ![tuxknight](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuxknight/32/34457_2.png) [@tuxknight](https://discuss.elastic.co/u/tuxknight)\
**Post date:** [April 28, 2016, 3:52pm UTC](https://discuss.elastic.co/t/logstash-s3-input-plugin-doesnt-work/48298/3 "2016-04-28T15:52:24Z")

</div>

Thanks for reply.

The error message came out again after I changed input-s3 plugin .  
And the connection to s3 server of aws cn-north-1 region was OK.  
By the way, logstash was running on a aws EC2 instance in cn-north-1 region.

```auto
ping s3.cn-north-1.amazonaws.com.cn
PING s3.cn-north-1.amazonaws.com.cn (54.222.21.2) 56(84) bytes of data.
64 bytes from 54.222.21.2: icmp_seq=1 ttl=59 time=2.14 ms
64 bytes from 54.222.21.2: icmp_seq=2 ttl=59 time=2.20 ms
64 bytes from 54.222.21.2: icmp_seq=3 ttl=59 time=2.15 ms

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:00am UTC](https://discuss.elastic.co/t/logstash-s3-input-plugin-doesnt-work/48298/4 "2017-07-06T05:00:09Z")

</div>


