Skip to main content
Question

AWS Firehose Integration

  • December 22, 2025
  • 1 reply
  • 68 views

Aravind3
Forum|alt.badge.img+8

Hi Everyone,

We’re trying to integrate AWS CloudWatch with Google SecOps using Amazon Data Firehose integration method, but we’re encountering the following error:

“The response received from the endpoint is invalid. See Troubleshooting HTTP Endpoints in the Firehose documentation for more information. Reason: Response for request {Masked} is not recognized as valid JSON or has unexpected fields. Raw response received: 403 { "error": { "code": 403, "message": "permission denied", "status": "PERMISSION_DENIED" } }”

For the Firehose HTTP endpoint, we configured the webhook URL in this format:
{ENDPOINT}?key={key}

We also entered the secret key in the Firehose Access key field. However, we’re still getting the error.

Could anyone please confirm if we’re configuring this correctly, or if there’s an additional steps we might be missing?

Thanks in advance,
Aravind

1 reply

bweidel
Staff
Forum|alt.badge.img+1
  • Staff
  • December 23, 2025
Here are the full instructions:

https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/aws-vpc#config-firehose