Chipper Access
Before Chipper can read logs from your S3 bucket, you need to create AWS IAM credentials with appropriate permissions. This one-time setup allows Chipper to securely access your log files.
What You'll Need
- AWS account with S3 and IAM access
- An S3 bucket containing your log files
- Permissions to create IAM users and policies
Step 1: Create an IAM User
-
Navigate to IAM Console
- Log into AWS Console
- Go to IAM (Identity and Access Management)
-
Create New User
- Click "Users" in the left sidebar
- Click "Create user"
- Enter a username (e.g.,
chipper-log-reader) - Click Next
Step 2: Set Permissions
Create a policy for the bucket Chipper will read:
- Select Attach policies directly, then Create policy → JSON.
- Replace
YOUR-BUCKET-NAMEin this policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:ListBucket", "s3:GetBucketLocation", "s3:GetBucketNotification"],
"Resource": "arn:aws:s3:::YOUR-BUCKET-NAME"
},
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::YOUR-BUCKET-NAME/*"
}
]
}
- Save the policy, attach it to the reader user, and finish creating the user.
s3:GetBucketNotification lets the instant-import wizard verify the notification destination.
It does not let Chipper edit the customer's bucket notifications. A storage administrator can
further restrict listing and object reads to the intended prefix; ensure the connection check and
actual log reads still succeed. SSE-KMS objects also require access to their encryption key.
Step 3: Generate Access Keys
-
Open the Created User
- Click on the username you just created
- Go to the Security credentials tab
-
Create Access Key
- Scroll to Access keys section
- Click "Create access key"
- Select "Third-party service" as the use case
- Click Next → Create access key
-
Save Your Credentials
- Copy the Access Key ID (starts with
AKIA...) - Copy the Secret Access Key (long random string)
⚠️ Important: The Secret Access Key is only shown once. Save it securely - you'll need both values for Chipper configuration.
- Copy the Access Key ID (starts with
What's Next?
Now that you have your credentials, you can:
- Set up Pull (Automated Polling) - Chipper checks for new files every hour
- Set up Push (Event Notifications) - Get instant notifications when files are uploaded (recommended for faster ingestion)
Troubleshooting
Access Denied Errors
Symptom: Chipper can't list or read files from your bucket
Solutions:
- Verify both resource ARNs in your IAM policy match your bucket name exactly:
arn:aws:s3:::your-bucket-name(for listing)arn:aws:s3:::your-bucket-name/*(for reading)
- Check that
s3:GetObjectANDs3:ListBucketare both allowed - Ensure the IAM user has the policy attached
Invalid Credentials
Symptom: Authentication errors when testing connection
Solutions:
- Verify you copied the full Access Key ID and Secret Access Key
- Check for extra spaces or line breaks when pasting
- Ensure the access key is still active (check IAM console)
Need Help?
If you encounter issues with AWS access setup, check:
- AWS IAM Documentation
- S3 Bucket Policies
- Contact support with your Access Key ID (never share your Secret Key!)