Issues getting cross account subscription for CW/Kinesis

0

Trying to follow this doc: https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CreateDestination.html

Stuck on step 7, getting error message "An error occurred (InvalidParameterException) when calling the PutDestination operation: Could not deliver test message to specified destination. Check if the destination is valid." Not sure what could be the issue

1 個回答
0

Hello,

Greetings for the day!

From the query description, I understand that you are getting the following error when creating a log destination by following the documentation and were stuck on Step 7. "An error occurred (InvalidParameterException) when calling the PutDestination operation: Could not deliver test message to specified destination. Check if the destination is valid". You would like to know the reason on what could cause this issue. Please feel free to correct me if I misunderstood your concern.

As per error description wording, "PutDestination operation: Could not deliver test message to specified destination. Check if the destination is valid" it mostly seems to be permission related issue and it can mostly happen whenever the Kinesis DataStream is encrypted with KMS and hence here the PutDestination API call also would need KMS access inorder to write the CloudWatch logs to the Kinesis DataStream. The IAM role used to create the destination should have KMS permissions. Please refer [1] for more information on it.

For detailed investigation, I would need to check whether the Kinesis stream is in the active state and whether the IAM role and destination policy is configured correctly or not, which I unable to check as I do not have the information of the resources with me. So, on a best effort basis, I have provided you general guidance regarding your query. To deep dive into this issue, we would need to check the resources and the permissions configured on them to proceed further.

In case, if you still have queries regarding this, I would like to request you to reach out to the support team, with all the resource details via Support console and we will investigate the same in detail.

Hope the information provided above is helpful.

Have a great day ahead!


References:

[1] Permissions to Use User-Generated KMS Master Keys - https://docs.aws.amazon.com/streams/latest/dev/permissions-user-key-KMS.html

AWS
Lavanya
已回答 1 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南