An AWS Elemental MediaLive input security group controls which source IP ranges can push media into a MediaLive push input. It does not control MediaLive’s delivery of an output to YouTube. First identify which direction is failing; then change the relevant ingress allow-list or output configuration—not both by guesswork.
First identify which leg of the stream is failing
A typical workflow has two separate connections: an encoder or upstream system sends video into MediaLive, and MediaLive sends its channel output onward to YouTube. An input security group applies to the first connection when the input is a supported push input. AWS documents YouTube delivery separately as an output workflow, including an HLS output group and YouTube upload destination in its 4K/HDR example (AWS Elemental MediaLive 4K/HDR tutorial).
- Encoder-to-MediaLive failure: Check the input type, source network path, and—where applicable—the MediaLive input security group’s IPv4 CIDR allow-list.
- MediaLive-to-YouTube failure: Check the channel’s output group, destination, and YouTube ingest configuration. Changing an input security group will not fix an output-side problem.
MediaLive distinguishes push inputs, where an upstream sender connects to MediaLive, from pull inputs, where MediaLive connects to a source. RTMP_PUSH and RTMP_PULL therefore require different diagnosis (MediaLive Inputs API reference).
Check whether the input uses an input security group
Non-VPC RTP or RTMP push input
A MediaLive input security group is an ingress allow-list: it identifies source IP address ranges permitted to push content to the input. AWS describes these restrictions for RTP and RTMP push inputs (MediaLive input security groups). For a non-VPC RTP or RTMP push input, compare the encoder’s actual public source IP with the IPv4 CIDR rules configured in the input security group. The API specifies IPv4 CIDR whitelist rules (MediaLive InputSecurityGroup API reference).
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
Do not use the encoder’s local or private LAN address unless that is genuinely the source address visible to MediaLive. A router, firewall, NAT gateway, or other network hop may change the public egress address. Verify the egress address for the same network path used by the encoder, and confirm that it is stable if the sender’s public IP can change.
Pull input
If the input is a pull type, MediaLive connects to the source; an input security group intended for push ingress is not the right first fix. Confirm the input type and diagnose the source URL, reachability, and connection direction. The API lists RTMP_PUSH and RTMP_PULL as distinct input types (MediaLive Inputs API reference).
Rank #2
VPC input
VPC inputs use VPC security group IDs and are not compatible with MediaLive’s inputSecurityGroups property. Check the VPC network security group and the relevant network path instead of trying to add a MediaLive input security group (MediaLive Inputs API reference).
Allow the verified encoder source IP
- Confirm the affected AWS context. In the AWS account and Region containing the workflow, identify the specific input, its type, whether it is VPC-based, and the input security group actually attached to it. Avoid changing a similarly named group or one in another Region.
- Verify the source address. Determine the encoder’s public egress IP on the path that sends the stream. Compare that address—not merely its local interface address—with the security group’s IPv4 CIDR whitelist.
- Adjust the allow-list narrowly. Add or edit the CIDR rule to cover the verified source address. Preserve the group’s access-restriction purpose; a broad allow-all rule is not a safe generic remedy. The group’s documented behavior and CIDR format are described by AWS (input security group documentation; API reference).
- Check input edit state before changing attached input settings. AWS permits endpoint fields for non-VPC RTP and RTMP push inputs to be edited, and an input can be assigned a different input security group. If the input is attached to a channel, edit it only while that channel is idle (Editing an input).
- Retry the upstream push and observe the result. If the encoder still cannot reach MediaLive, re-check the input type, attached group, actual egress address, and exact error before broadening access or changing unrelated settings.
If MediaLive is failing to deliver the output to YouTube
Treat this as an output-side issue. Inspect the MediaLive channel’s output group and destination, then verify that the protocol, ingest URL, and any stream-key details match the current YouTube event configuration. AWS’s YouTube workflow example is an HLS output configuration; it does not make an input security group part of YouTube delivery (AWS 4K/HDR tutorial).
Recommended Free Tools
Keep the two legs separate when reading errors: a successful encoder-to-input connection does not establish that the channel can reach YouTube, and a YouTube output error alone does not show that the input security group is blocking anything.
Troubleshoot by symptom
| Symptom or condition | Likely distinction to check | Next action |
|---|---|---|
| Encoder cannot push to a non-VPC RTP or RTMP input | Input security group may not include the sender’s actual public source IP. | Verify the egress IP and compare it with the attached group’s IPv4 CIDR whitelist. |
| The configured address looks correct, but the push is still denied | The encoder may egress through NAT or another network hop, or the wrong group, input, account, or Region may have been checked. | Confirm the observed public source address and the precise input-to-group association. |
| Input type is RTMP_PULL | MediaLive initiates the connection rather than accepting an encoder push. | Check source reachability and pull configuration; do not treat push ingress rules as the default fix. |
| Input is VPC-based | VPC networking uses VPC security group IDs, not MediaLive’s inputSecurityGroups property. |
Review the VPC security group and network path. |
| MediaLive receives the input, but YouTube does not receive the channel output | The fault is on the output leg, not the input security group. | Inspect the output group and destination, and compare the ingest details with the current YouTube event configuration. |
| You need to edit an input attached to an active channel | AWS requires the channel to be idle for the applicable attached-input edit. | Plan the change for when the channel is idle, following AWS’s input-edit guidance. |
Or let it run in the cloud
If your goal is simply to keep uploaded video playing as a 24/7 YouTube stream, StreamNeo is a separate cloud option—not a fix for a misconfigured MediaLive input. Upload a recording or build a playlist, add your YouTube stream key once, and go live. Nothing has to stay on at home; each slot streams the upload as made, up to 4K 60fps, at one flat price per slot; and it automatically recovers if YouTube drops the stream. The first day is free with no card. Monthly pricing is $9.99 per month. Learn more at StreamNeo, or start the free first day.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




