# Metricbeat not pulling logs from AWS CWAgent namespace

**URL:** <https://discuss.elastic.co/t/metricbeat-not-pulling-logs-from-aws-cwagent-namespace/277119>\
**Category:** Beats\
**Tags:** beats-module, metricbeat\
**Created:** [June 26, 2021, 10:48am UTC](https://discuss.elastic.co/t/metricbeat-not-pulling-logs-from-aws-cwagent-namespace/277119 "2021-06-26T10:48:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sumeshms](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sumeshms/32/10409_2.png) [@sumeshms](https://discuss.elastic.co/u/sumeshms)\
**Post date:** [June 26, 2021, 10:48am UTC](https://discuss.elastic.co/t/metricbeat-not-pulling-logs-from-aws-cwagent-namespace/277119/1 "2021-06-26T10:48:29Z")

</div>

Hello

I am trying to pull logs from AWS Cloudwatch metricset with the below configuration. Unfortunately no logs received at the metricbeat end.

```auto
- module: aws
  period: 300s
  access_key_id: 'xxxxxxx'
  secret_access_key: 'xxxxxxxxxx'
  default_region: 'me-south-1'
  metricsets:
    - cloudwatch
  metrics:
    - namespace: CWAgent
      statistic: "Average"
      name: "LogicalDisk % Free Space"
      dimensions:
      - name: instance
        value: C:
      - name: InstanceId
        value: i-xxxxxxxxxxx
      - name: ImageId
        value: ami-xxxxxxxxx
      - name: objectname
        value: LogicalDisk
      - name: InstanceType
        value: m5.large

```

Interesting fact is that the same parameters pull data from the the aws cli with same credentials!  
Any thoughts ?

```auto
aws cloudwatch get-metric-statistics --namespace CWAgent --metric-name "LogicalDisk % Free Space" --dimensions Name=instance,Value=C: Name=InstanceId,Value=i-xxxxxxx Name=ImageId,Value=ami-xxxxxxx Name=objectname,Value=LogicalDisk Name=InstanceType,Value=m5.large --start-time 2021-06-25T00:00:00Z --end-time 2021-06-25T00:10:00Z --period 300 --statistics Average

{
    "Label": "LogicalDisk % Free Space",
    "Datapoints": [
        {
            "Timestamp": "2021-06-25T00:00:00+00:00",
            "Average": 20.8502197265625,
            "Unit": "None"
        },
        {
            "Timestamp": "2021-06-25T00:05:00+00:00",
            "Average": 20.8502197265625,
            "Unit": "None"
        }
    ]
}

```

Any thoughts on this please? Thanks in advance.

Sumesh

---

<div class="post-metadata">

**Author:** ![sumeshms](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sumeshms/32/10409_2.png) [@sumeshms](https://discuss.elastic.co/u/sumeshms)\
**Post date:** [June 29, 2021, 3:58pm UTC](https://discuss.elastic.co/t/metricbeat-not-pulling-logs-from-aws-cwagent-namespace/277119/2 "2021-06-29T15:58:26Z")

</div>

Finally it worked - the correct format of yml file is expained here - thanks

[Metricbeat AWS Cloudwatch Agent Log-shipping (cloudcybersafe.com)](https://www.cloudcybersafe.com/metricbeat-aws-cloudwatch-agent-log-shipping/)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2021, 5:58pm UTC](https://discuss.elastic.co/t/metricbeat-not-pulling-logs-from-aws-cwagent-namespace/277119/3 "2021-07-27T17:58:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
