# Parsing S3 bucket into Logstash

**URL:** <https://discuss.elastic.co/t/parsing-s3-bucket-into-logstash/237996>\
**Category:** Logstash\
**Created:** [June 22, 2020, 4:34am UTC](https://discuss.elastic.co/t/parsing-s3-bucket-into-logstash/237996 "2020-06-22T04:34:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![SunilYadav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilyadav/32/70752_2.png) [@SunilYadav](https://discuss.elastic.co/u/SunilYadav)\
**Post date:** [June 22, 2020, 4:34am UTC](https://discuss.elastic.co/t/parsing-s3-bucket-into-logstash/237996/1 "2020-06-22T04:34:59Z")

</div>

Hi Team,

when I am trying to use the S3 input plugin.

S3 location:s3://bucket123/DAG/TASK/2020-04-26T16:01:00+00:00/1.log  
'''  
The resulting error is :  
S3 input: Unable to download remote file {:remote\_key=\>"bucket123/DAG/TASK/2020-04-26T16:01:00 00:00/1.log", :message=\>"The specified key does not exist."}  
'''  
'''  
This issue only occurs when the key consists of the "+" symbol which seems to be replaced with a space when returned to logstash.'''

The key can be found but the file just cannot be downloaded.

Can you please help and provide guidance on this?

---

<div class="post-metadata">

**Author:** ![SunilYadav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilyadav/32/70752_2.png) [@SunilYadav](https://discuss.elastic.co/u/SunilYadav)\
**Post date:** [June 23, 2020, 4:28am UTC](https://discuss.elastic.co/t/parsing-s3-bucket-into-logstash/237996/2 "2020-06-23T04:28:59Z")

</div>

Guys , any link on this?  
is this possible in logstash?

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [June 26, 2020, 11:59am UTC](https://discuss.elastic.co/t/parsing-s3-bucket-into-logstash/237996/3 "2020-06-26T11:59:16Z")

</div>

Hi @SunilYadav - Welcome to our community forums!

As mentioned in [Object key and metadata](https://docs.aws.amazon.com/AmazonS3/latest/dev/UsingMetadata.html), the `+` character in a key name might require additional code handling and likely need to be URL encoded or referenced as HEX.

Could you try to change the prefix value accordingly? You could use [this online tool](https://www.urlencoder.org/) to get the encoded string. For example:

- `XXXX/yyyy/2020-06-27T12:00:00+00:00` would be become `XXXX%2Fyyyy%2F2020-06-27T12%3A00%3A00%2B00%3A00`

Let us know if that works.

Note: FYI, there is an [existing issue](https://github.com/logstash-plugins/logstash-input-s3/issues/211) for the same problem in the respective Github repository.

---

<div class="post-metadata">

**Author:** ![SunilYadav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilyadav/32/70752_2.png) [@SunilYadav](https://discuss.elastic.co/u/SunilYadav)\
**Post date:** [June 29, 2020, 9:30am UTC](https://discuss.elastic.co/t/parsing-s3-bucket-into-logstash/237996/4 "2020-06-29T09:30:47Z")

</div>

Hi Romain,  
Thanks for your reply!

We have tried this already and its not working giving the error "no file found in bucket".

What are the other options available?

Thanks,  
Sunil Yadav

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2020, 9:30am UTC](https://discuss.elastic.co/t/parsing-s3-bucket-into-logstash/237996/5 "2020-07-27T09:30:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
