First identify which connection is failing: an encoder pushing into an AWS Elemental MediaLive input, or MediaLive sending its output to YouTube. An input security group controls allowed source IP ranges for push inputs; it does not configure MediaLive’s YouTube output. If the failure is on the YouTube delivery leg, changing the input security group is the wrong fix.
What a MediaLive input security group controls
An AWS Elemental MediaLive input security group is an ingress allow-list: it identifies source IP address ranges permitted to push content into a push input. AWS describes input security groups as access restrictions for RTP and RTMP push inputs. AWS: Input security groups.
This is separate from a MediaLive channel output sent to YouTube. AWS’s YouTube delivery example is an output workflow using an HLS output group and a YouTube upload destination. A failure in that direction calls for checking the output group and destination, not the input’s ingress allow-list. AWS: Setting up for HDR.
Diagnose the failing connection before changing settings
- Determine the direction. Is an encoder or upstream system unable to push into MediaLive, or is MediaLive unable to deliver its channel output to YouTube? Push inputs accept an upstream connection; with pull inputs, MediaLive connects to the source. AWS: Supported input types.
- Check the input type and network model. The MediaLive API distinguishes
RTMP_PUSHfromRTMP_PULL. Input security groups apply to push inputs. VPC inputs instead use VPC security group IDs and cannot use theinputSecurityGroupsproperty. AWS Elemental MediaLive API: Inputs. - Confirm the actual public source IP for a non-VPC push input. Compare the encoder’s public egress address, as seen over the actual network path, with the input security group’s IPv4 CIDR whitelist. A workstation’s local or private address may not be the public address AWS sees; verify the egress IP at the network boundary used by the encoder.
- Verify the AWS context. Confirm the account, Region, MediaLive input, and security group attached to that input. A correct CIDR added to a different group or Region will not resolve the affected input’s ingress restriction.
Allow the encoder’s IP on a non-VPC push input
- In the AWS Elemental MediaLive console, open the relevant input in the account and Region where it runs. Confirm that it is an RTP or RTMP push input, rather than a pull or VPC input.
- Inspect the input’s attached input security group and its IPv4 CIDR whitelist. Compare those entries with the verified public source address used by the encoder.
- Add or adjust the narrowest CIDR rule that includes the verified source address. For a single fixed IPv4 address, use its individual-address CIDR rather than opening access broadly. The API defines whitelist rules as IPv4 CIDR addresses. AWS Elemental MediaLive API: Input security groups.
- Save the change, then retry the encoder connection and check whether MediaLive receives the input. If the encoder’s egress IP can change, coordinate with the network operator to establish the actual stable egress range or update the allow-list when it changes.
Do not use an unrestricted allow-all CIDR as a generic troubleshooting shortcut. The security group’s purpose is to restrict which source ranges may push to the input; widen access only when there is a specific, justified network requirement.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
Account for input type and edit state
RTMP or RTP push input
For a non-VPC RTP or RTMP push input, check the input security group’s allowed source CIDRs against the encoder’s verified public source IP. AWS allows endpoint fields on these input types to be edited, and an input can be assigned a different input security group. If the input is attached to a channel, make the edit only while that channel is idle. AWS: Editing an input.
RTMP pull input
With RTMP_PULL, MediaLive connects to the source. That is the opposite connection direction from an encoder pushing into MediaLive, so an input security group allow-list for push traffic is not the first setting to change. Check the source connection and the pull-input configuration instead.
Rank #2
VPC input
For a VPC input, use the VPC networking and security-group configuration applicable to that input. MediaLive’s inputSecurityGroups property is not compatible with VPC inputs; adding the encoder address to a MediaLive input security group will not fix VPC access.
If MediaLive is failing to send its output to YouTube
When MediaLive accepts its input but YouTube does not receive the channel output, inspect the output group, protocol, destination, and current YouTube event ingest details. AWS’s documented YouTube example uses an HLS output group and a YouTube upload destination; it is an output-side setup, distinct from input security-group ingress. Confirm that the output protocol and ingest URL match the current YouTube event configuration. AWS: Setting up for HDR.
Common symptoms and what to check
| Symptom | Likely issue to verify | Next check |
|---|---|---|
| Encoder cannot push to an RTMP or RTP input | The encoder’s actual public source IP is not covered by the attached input security group’s IPv4 CIDR rules. | Verify the public egress address, input type, account, Region, and attached group; add a narrow matching CIDR. |
| Changing the MediaLive input security group has no effect on a VPC input | VPC inputs use VPC security groups and do not support the MediaLive inputSecurityGroups property. |
Check the VPC network path and applicable VPC security-group rules. |
| MediaLive input works, but YouTube does not receive the stream | The failure is on the channel output-to-YouTube leg, not necessarily input ingress. | Check the output group, output protocol, destination, and current YouTube event ingest configuration. |
| An edit to an input attached to a channel cannot be made as expected | The channel may not be idle. | Make the input edit only when its attached channel is idle. |
Or let it run in the cloud
If your goal is to keep a pre-recorded YouTube stream running 24/7 rather than operate a MediaLive input-to-output workflow, StreamNeo is a separate option: upload a recording or build a playlist, add your YouTube stream key once, and go live. It loops uploaded videos from the cloud, so no computer or home connection has to stay on. Each slot streams the uploaded quality up to 4K 60fps at one flat price per slot, and automatically recovers if YouTube drops the stream. The first day is free with no card; one free day is available per account.
Monthly: $9.99 per month. See StreamNeo, or start your free day.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




