# Metricbeat connecting to AWS reporting Failed DescribeRegions

**URL:** <https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [October 3, 2019, 6:59am UTC](https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100 "2019-10-03T06:59:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![alesanchez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alesanchez/32/60189_2.png) [@alesanchez](https://discuss.elastic.co/u/alesanchez)\
**Post date:** [October 3, 2019, 6:59am UTC](https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100/1 "2019-10-03T06:59:47Z")

</div>

Hi again everyone,  
I installed the aws module for metricbeat with the following configuration:  
# Module: aws  
# Docs: [https://www.elastic.co/guide/en/beats/metricbeat/7.4/metricbeat-module-aws.html](https://www.elastic.co/guide/en/beats/metricbeat/7.4/metricbeat-module-aws.html)

```
- module: aws
period: 300s
metricsets:
    - cloudwatch
access_key_id: '${AWS_ACCESS_KEY_ID:""}'
secret_access_key: '${AWS_SECRET_ACCESS_KEY:""}'
metrics:
    - namespace: AWS/EC2
    name: ["CPUUtilization", "DiskWriteOps"]
    tags.resource_type_filter: ec2:instance
    dimensions:
        - name: InstanceId
        value: i-091a26785c02342bc
    statistic: ["Average", "Maximum"]

```

The key id and the secret key env vars are in the .bashrc file and are correctly set. Those keys are for a user created in IAM with a policy with the following permissions:  
 ![permissions](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c2f0c38e6ada2cfecd9281a1cf4a8f740cccda4.png)

I followed the tutorial in:  
[https://www.elastic.co/guide/en/beats/metricbeat/master/metricbeat-module-aws.html](https://www.elastic.co/guide/en/beats/metricbeat/master/metricbeat-module-aws.html)

But when I do:  
metricbeat setup  
metricbeat -e

I get the following error:

```
Exiting: 1 error: error creating aws metricset: Failed DescribeRegions: EC2RoleRequestError: no EC2 instance role found

caused by: EC2MetadataError: failed to make Client request
caused by:

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
    <title>404 - Not Found</title>
</head>

<body>
    <h1>404 - Not Found</h1>
</body>

</html>

```

Am I doing something wrong?

Thank you very much.

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [October 3, 2019, 4:10pm UTC](https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100/2 "2019-10-03T16:10:54Z")

</div>

Hello! Thanks for posting here. `Failed DescribeRegions` usually means something wrong with the credentials (probably I need to fix this with better error messages).

First question I have is, do you need a `session_token` for your aws credential? For example if you have MFA setup, then you need to use the temporary token to generate a new set of access key, secret access key and session token.

If you have aws-cli setup locally, you can try to make some basic aws api calls with the credential you have to see if the credentials are valid.

---

<div class="post-metadata">

**Author:** ![alesanchez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alesanchez/32/60189_2.png) [@alesanchez](https://discuss.elastic.co/u/alesanchez)\
**Post date:** [October 4, 2019, 7:05am UTC](https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100/3 "2019-10-04T07:05:04Z")

</div>

Hmmm, good question. I'm reviewing the user. I created a new one just for metricbeat. With the roles I mentioned above. Also, the user has no password nor MFA. Only the access keys. This is the user configuration:

 ![01](https://us1.discourse-cdn.com/elastic/original/3X/8/8/8873d1c35ca4bce349e308ddcb7325abcec1f3d0.png)

I made a policy simulation in IAM and the DescribeRegions worked fine. You mean that maybe I need to configure in the `aws.yaml` file both the `access_key` and the `session_token` vars?

I'll try to sep up aws-cli to use those credentials and see if it works. Thanks you!

---

<div class="post-metadata">

**Author:** ![alesanchez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alesanchez/32/60189_2.png) [@alesanchez](https://discuss.elastic.co/u/alesanchez)\
**Post date:** [October 4, 2019, 8:21am UTC](https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100/4 "2019-10-04T08:21:04Z")

</div>

Quick update. I configured the AWS cli with the same keys as in metricbeat, run the command `aws ec2 describe-regions` and got the following output:

```
{
    "Regions": [
        {
            "OptInStatus": "opt-in-not-required",
            "Endpoint": "ec2.eu-north-1.amazonaws.com",
            "RegionName": "eu-north-1"
        },
        ...
    ]
}

```

With the same OptInStatus in every region.

Don't know if I'm doing anything wrong or if I can get more info about what is happening with metricbeat.

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [October 18, 2019, 5:48pm UTC](https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100/5 "2019-10-18T17:48:47Z")

</div>

Sorry for the late response. Thanks for giving the CLI a try, since that works, the credentials should work for aws module hmmm. Do you use `~/.aws/credentials` to store aws credentials under different profile names? If so, could you give this config a try?

```auto
- module: aws
  period: 300s
  credential_profile_name: test-mb
  metricsets:
    - cloudwatch
  metrics:
    - namespace: AWS/EC2
      name: ["CPUUtilization", "DiskWriteOps"]
      tags.resource_type_filter: ec2:instance
      statistic: ["Average"]

```

If you don't use `~/.aws/credentials` file, then could you plugin the AWS credentials directly into the config to see if that will work? I'm just trying to make sure the credentials get passed into the config correctly:

```auto
- module: aws
  period: 300s
  access_key_id: "please copy paste your access key id in here"
  secret_access_key: "please copy paste your secret access key in here"
  metricsets:
    - cloudwatch
  metrics:
    - namespace: AWS/EC2
      name: ["CPUUtilization", "DiskWriteOps"]
      tags.resource_type_filter: ec2:instance
      statistic: ["Average"]

```

---

<div class="post-metadata">

**Author:** ![alesanchez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alesanchez/32/60189_2.png) [@alesanchez](https://discuss.elastic.co/u/alesanchez)\
**Post date:** [October 22, 2019, 6:41am UTC](https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100/6 "2019-10-22T06:41:40Z")

</div>

Hi again Kaiyan!

It looks like, as you said, the credentials were not passed correctly to the config file. I had an `.aws/credentials` file, with just a `default` profile. I used it in the config file and it seems that it's working fine.

Probably I did something wrong with the ENV variables in the yaml file.

Thank you very much for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2019, 6:41am UTC](https://discuss.elastic.co/t/metricbeat-connecting-to-aws-reporting-failed-describeregions/202100/7 "2019-11-19T06:41:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
