# Graylog Plugin AWS

**URL:** <https://community.graylog.org/t/graylog-plugin-aws/867>\
**Category:** Graylog Add-ons\
**Created:** [April 20, 2017, 11:11am UTC](https://community.graylog.org/t/graylog-plugin-aws/867 "2017-04-20T11:11:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![SnazzyBootMan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/snazzybootman/32/8392_2.png) [@SnazzyBootMan](https://community.graylog.org/u/SnazzyBootMan)\
**Post date:** [April 20, 2017, 11:11am UTC](https://community.graylog.org/t/graylog-plugin-aws/867/1 "2017-04-20T11:11:23Z")

</div>

So I was looking at setting up the AWS Plugin so ingest Flowlogs and then CloudTrail events.

It was all going well until “Step 4” in the readme for Flowlogs - Launching a new input.

The region I am using (eu-west-2 - London) is missing from the AWS Region drop down.

So my question is if London is available what is the minimum version I need to upgrade to? I am currently on Graylog 2.1.1, would 2.1.3 (with plugin 1.2.1) have this region available?

I also noticed that plugin version 1.2.0 also only has the ability to add one set of AWS Credentials thus limiting the usefulness of the plugin. Has this been addressed in later versions? How are multiple accounts handled?

Any constructive input would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [April 20, 2017, 12:11pm UTC](https://community.graylog.org/t/graylog-plugin-aws/867/2 "2017-04-20T12:11:51Z")

</div>

> [@SnazzyBootMan](#):
>
> I am currently on Graylog 2.1.1, would 2.1.3 (with plugin 1.2.1) have this region available?

Yes, that version should include the eu-west-2 region (which was added in [awsk-sdk-java 1.11.67](https://github.com/aws/aws-sdk-java/releases/tag/1.11.67)).

> [@SnazzyBootMan](#):
>
> How are multiple accounts handled?

That’s currently not supported.

> <https://github.com/Graylog2/graylog-plugin-aws/issues/13>
>
> Due to the changes in c85cbbe079eef1075e088a20b95efa9046140393 it is now impossi…ble to run this plugin multiple times for different AWS accounts on the same Graylog cluster.

---

<div class="post-metadata">

**Author:** ![SnazzyBootMan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/snazzybootman/32/8392_2.png) [@SnazzyBootMan](https://community.graylog.org/u/SnazzyBootMan)\
**Post date:** [April 20, 2017, 12:36pm UTC](https://community.graylog.org/t/graylog-plugin-aws/867/3 "2017-04-20T12:36:53Z")

</div>

Thanks @jochen - I will look at upgrading tomorrow and delve into the pain of cross account access.

---

<div class="post-metadata">

**Author:** ![SnazzyBootMan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/snazzybootman/32/8392_2.png) [@SnazzyBootMan](https://community.graylog.org/u/SnazzyBootMan)\
**Post date:** [April 21, 2017, 11:09am UTC](https://community.graylog.org/t/graylog-plugin-aws/867/4 "2017-04-21T11:09:26Z")

</div>

Hello @jochen, I upgraded GrayLog server to 2.1.3 and the AWS plugin to 1.2.1 and I can now add eu-west-2 but I am seeing an API call error in the server log file.

```
2017-04-21T11:56:56.061+01:00 ERROR [InstanceLookupTable] Error when trying to refresh AWS instance lookup table in [eu-west-2] com.amazonaws.SdkClientException: Unable to execute HTTP request: Connect to ec2.eu-west-2.amazonaws.com:443 [ec2.eu-west-2.amazonaws.com/52.94.56.52] failed: connect timed out

```

I have tried adding both [dynamodb.eu-west-2.amazonaws.com](http://dynamodb.eu-west-2.amazonaws.com) and [ec2.eu-west-2.amazonaws.com](http://ec2.eu-west-2.amazonaws.com) to the proxy allowed list and I can hit both these URLs from the command line on the GrayLog server. I have also tried turning off the proxy filter (thus allowing all outbound traffic) and the CLI give the same results (using curl).

I must have missed something, have you seen this before?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [April 21, 2017, 11:53am UTC](https://community.graylog.org/t/graylog-plugin-aws/867/5 "2017-04-21T11:53:01Z")

</div>

I don’t think that the Graylog AWS plugin currently supports using proxy servers for all parts.

---

<div class="post-metadata">

**Author:** ![SnazzyBootMan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/snazzybootman/32/8392_2.png) [@SnazzyBootMan](https://community.graylog.org/u/SnazzyBootMan)\
**Post date:** [April 21, 2017, 12:18pm UTC](https://community.graylog.org/t/graylog-plugin-aws/867/6 "2017-04-21T12:18:48Z")

</div>

@jochen - that’s okay the routing table handles the proxy and even with the proxy turned off I still get:

```
 2017-04-21T12:51:56.694+01:00 ERROR [LeaseManager] Failed to get table status for graylog-aws-plugin
```

---

<div class="post-metadata">

**Author:** ![SnazzyBootMan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/snazzybootman/32/8392_2.png) [@SnazzyBootMan](https://community.graylog.org/u/SnazzyBootMan)\
**Post date:** [April 21, 2017, 3:12pm UTC](https://community.graylog.org/t/graylog-plugin-aws/867/7 "2017-04-21T15:12:54Z")

</div>

@jochen - I notice that AWSPluginConfiguration.jsx in v1.3.2 mentions:

```
help={When enabled, we'll access the AWS APIs through the HTTP proxy configured (http_proxy_uri) in your Graylog configuration file. Important: You might have to restart AWS message inputs for this configuration to take effect.}

```

So i guess that newer versions of the Plugin can deal with a Proxy (no mention of HTTPS) and that my /etc/environment proxy settings is being ignored. I think I might have to upgrade again to the latest versions.
