# Logstash S3 plugin cannot assume a across-account role with external\_id

**URL:** <https://discuss.elastic.co/t/logstash-s3-plugin-cannot-assume-a-across-account-role-with-external-id/278623>\
**Category:** Logstash\
**Created:** [July 14, 2021, 7:33am UTC](https://discuss.elastic.co/t/logstash-s3-plugin-cannot-assume-a-across-account-role-with-external-id/278623 "2021-07-14T07:33:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![wilsonwang](https://avatars.discourse-cdn.com/v4/letter/w/e480ec/32.png) [@wilsonwang](https://discuss.elastic.co/u/wilsonwang)\
**Post date:** [July 14, 2021, 7:33am UTC](https://discuss.elastic.co/t/logstash-s3-plugin-cannot-assume-a-across-account-role-with-external-id/278623/1 "2021-07-14T07:33:03Z")

</div>

I am using logstash S3 plugin which installed on an EC2 to ingest log from S3 in another account B.

It runs well we I configure the role\_arn in conf of S3 plugin, but when a external\_ID is added to the role, the problem comes, there is no way to configure the external\_ID in the plugin. and always got a access denied, I am reading the following doc but nothing helps.  
Is there any way I can do with this? It is mandatary for account B to configure this external\_ID.

> **[S3 input plugin | Logstash Reference \[7.13\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-s3.html#plugins-inputs-s3-role_arn)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2021, 7:33am UTC](https://discuss.elastic.co/t/logstash-s3-plugin-cannot-assume-a-across-account-role-with-external-id/278623/2 "2021-08-11T07:33:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
