IBM Support

QRadar: AWS Cloudtrail displays error "No new files matching the directory prefix and file pattern"

Troubleshooting


Problem

Log source is displaying a warning status with the following messages:

No new files matching the directory prefix and file pattern.
No download errors, but no files were processed.
This technote is intended for S3 Bucket, but it can also apply for SQS events.

Symptom

No events are being pulled from AWS. An error message is displayed in the Log Source management app.
If you run the test in the log source management app, it runs successfully and displays events that are in the S3 bucket.

image 10800

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwt0AAA","label":"Log Source"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.3.3;7.4.0;7.4.1;7.4.2;7.4.3"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
18 July 2022

UID

ibm16462535