# Need help figuring out AWS role for functionbeat

**URL:** <https://discuss.elastic.co/t/need-help-figuring-out-aws-role-for-functionbeat/261297>\
**Category:** Beats\
**Tags:** functionbeat\
**Created:** [January 15, 2021, 9:26pm UTC](https://discuss.elastic.co/t/need-help-figuring-out-aws-role-for-functionbeat/261297 "2021-01-15T21:26:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jonathan\_Detert](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonathan_detert/32/80849_2.png) [@Jonathan\_Detert](https://discuss.elastic.co/u/Jonathan_Detert)\
**Post date:** [January 15, 2021, 9:26pm UTC](https://discuss.elastic.co/t/need-help-figuring-out-aws-role-for-functionbeat/261297/1 "2021-01-15T21:26:36Z")

</div>

[https://www.elastic.co/guide/en/beats/functionbeat/7.x/configuration-functionbeat-options.html#functionbeat-role](https://www.elastic.co/guide/en/beats/functionbeat/7.x/configuration-functionbeat-options.html#functionbeat-role) says that I can add a parameter named `role` to my functionbeat config.

Where to add it? I'm guessing it's meant as an attribute of an item in the `functionbeat.provider.aws.functions` list. Is that correct? If not, where to put it?

The value of the `role` attribute is said to be an aws role's arn. [https://www.elastic.co/guide/en/beats/functionbeat/7.x/iam-permissions.html](https://www.elastic.co/guide/en/beats/functionbeat/7.x/iam-permissions.html) describes the actions that need to be in the role policy, but does not say anything about which resources these actions will be allowed on. It just cites '\*' for the resource. My employer's policy doesn't allow me to say that. So, I have to be more specific. What resources should I cite as part of the policy?

Thanks!

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [January 18, 2021, 9:08am UTC](https://discuss.elastic.co/t/need-help-figuring-out-aws-role-for-functionbeat/261297/2 "2021-01-18T09:08:53Z")

</div>

> [@Jonathan\_Detert](#):
>
> Where to add it? I'm guessing it's meant as an attribute of an item in the `functionbeat.provider.aws.functions` list. Is that correct? If not, where to put it?

Please look at the docs: [Configure AWS functions | Functionbeat Reference [7.16] | Elastic](https://www.elastic.co/guide/en/beats/functionbeat/7.x/configuration-functionbeat-options.html#configuration-functionbeat-options)

```auto
functionbeat.provider.aws.functions:
  - name: cloudwatch
    enabled: true
    type: cloudwatch_logs
    description: "lambda function for cloudwatch logs"
    triggers:
      - log_group_name: /aws/lambda/my-lambda-function
    role: arn:aws:iam::123456789012:role/MyFunction

```

---

<div class="post-metadata">

**Author:** ![Jonathan\_Detert](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonathan_detert/32/80849_2.png) [@Jonathan\_Detert](https://discuss.elastic.co/u/Jonathan_Detert)\
**Post date:** [January 18, 2021, 9:16pm UTC](https://discuss.elastic.co/t/need-help-figuring-out-aws-role-for-functionbeat/261297/3 "2021-01-18T21:16:41Z")

</div>

Obviously, I have looked at that url - it's the same one I put in my original post. And, if you have a look, you will see that it neither explicitly says where to put it, nor shows an example. Your example matches what I posted as a guess. It would be clearer for all if the doc simply said so, or if you had said , "yes, that is the implied location".

What about my 2nd question? Which resources to cite in the policy?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2021, 11:16pm UTC](https://discuss.elastic.co/t/need-help-figuring-out-aws-role-for-functionbeat/261297/4 "2021-02-15T23:16:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
