FILENAME Statement: S3 Access Method

Enables you to access data objects in an Amazon S3 or MinIO environment.

Valid in:Anywhere
Category:Data Access
Supports: PROC S3 statement options
See:S3 Procedure in Base SAS Procedures Guide

Syntax

Required Arguments

fileref

is a valid fileref.

S3

specifies the S3 access method.

object-path

specifies the S3 object that you want to access.

Optional Arguments

The S3 access method supports PROC S3 options as well as the following:

ACL="canned-ACL-value"

specifies the canned ACL value that applies to a new file in the specified object path.

Here are the valid values:

authenticated-readlog-delivery-write
aws-exec-readprivate
bucket-owner-full-controlpublic-read
bucket-owner-readpublic-read-write

For more information about these values, see Amazon S3 Canned ACL documentation.

Defaultprivate
RequirementThe location that you specify must be within an ACL-enabled S3 bucket.
NoteSupport for this option was added in 2024.10.
ExampleAssign a canned ACL value to a new file.
filename myfile s3 "/mybucket/newfile.txt" acl="bucket-owner-full-control";

ENCODING="encoding-value"

specifies the encoding to use when SAS is reading from or writing to an object stored in the Amazon S3 or MinIO environment. The value for ENCODING= indicates that the external file has a different encoding from the current session encoding.

DefaultSAS assumes that an external file is in the same encoding as the session encoding.
SeeFor valid encoding values, see Encoding Values in SAS Language Elements in SAS National Language Support (NLS): Reference Guide.
Specify an Encoding Scheme When Reading and Writing to an Amazon S3 Object

Details

Using the S3 Access Method

The S3 access method enables you to access objects in the Simple Storage Service (S3) of Amazon or MinIO.

The SAS Viya platform supports S3 or MinIO Enterprise Object Store as a data source in AWS. You can use the S3 FILENAME statement to connect the Compute Server with your Amazon S3 or MinIO data source. For more information, see Support for Data Storage in Amazon S3 and MinIO in System Requirements for the SAS Viya Platform.

Before you can use the S3 access method, you need an AWS access key ID and a secret access key. When using temporary credentials, you also need a security token.

Support for the ENCKEY Statement

The S3 access method supports the ENCKEY statement of PROC S3. The ENCKEY statement supports server-side encryption in an Amazon S3 or MinIO environment. For an example that shows how to encrypt data in an Amazon S3 environment, see Using the S3 Access Method with the ENCKEY Statement. For information about the ENCKEY statement, see ENCKEY Statement in Base SAS Procedures Guide.

Examples

Example 1: Reading a File by Using the S3 Access Method

This example uses the S3 access method to read a file in an Amazon S3 environment. The FILENAME statement creates a fileref (myfile), which points to the location of the file, filename.txt, on the Amazon S3 server. The DATA step reads the file and writes its contents to the SAS log.

filename myfile s3 '/directory1/filename.txt';
 
data _null_;
  infile myfile;
  input;
  put _infile_;
run;

Example 2: Sending a Log Output to a New Destination by Using the S3 Access Method

This example uses the S3 access method with PROC PRINTTO to route a log output to a file, log.txt, on the Amazon S3 server. The NEW option removes any information that is in the file and prepares the file to receive the output. For more information, see PRINTTO Procedure in Base SAS Procedures Guide.

The S3 access method in the FILENAME statement provides an alias and pointer to the location of the log.txt file on AWS. The LOG= option in PROC PRINTTO specifies that all log output is sent to the external file on AWS. You can also specify the PRINT= option in the PRINTTO statement so that all procedure output is sent to an external file.

filename mylog s3 "/directory1/userid/log.txt" ;

proc printto log=mylog new; 
run;

proc print data=sashelp.cars;
run;

proc printto; 
run;

Example 3: Importing a File by Using the S3 Access Method

This example uses PROC IMPORT with the S3 access method to import a file to a SAS data set from an Amazon S3 environment.

filename i s3 '/directory1/i.cvs' ;

proc import datafile=i out=work.i replace dbms=csv debug;
  getnames=yes;
  datarow=2;
  guessingrows=all;
run;

Example 4: Using the S3 Access Method with the ENCKEY Statement

This example uses the SAS DATA step with PROC S3 and the ENCKEY statement to encrypt a server-side file in an Amazon S3 environment.

proc s3;
  enckey add name="mykey"                                                     /* 1 */
  hexkey="7468697349734d6f726546726565666f726d49735550506f7365736f79656168";
run;

filename myfile s3 "/directory1/filename.txt" enckey=mykey;             /* 2 */

data _null_;                                                                  
  file myfile;                                                                /* 3 */
  put 'Write with enckey';
run;
  1. The ENCKEY statement in PROC S3 creates the encryption key and stores it in the name mykey.

  2. The FILENAME statement creates an alias (myfile) and uses the S3 access method to associate the alias with the S3 server file, filename.txt. The S3 access method uses the ENCKEY= option to send the encryption information to the S3 server where the data in filename.txt is encrypted.

  3. The FILE statement in the DATA step uses the alias for the S3 server file to specify that the PUT statement output is written to the server file.

Example 5: Specify an Encoding Scheme When Reading and Writing to an Amazon S3 Object

The following example uses the ENCODING= option to read and write to the u8.txt file using the UTF-8 encoding scheme.

filename myout s3 "/my-dir/u1.txt" 
               awsconfig="/u/qz/.aws/config" 
               awscredentials="/u/qz/.aws/credentials" 
               encoding="utf-8";

data _null_;
   file myout;
   put "create utf8 text file";
   put "line1";
   put "line2";
   put "bye";
run;

filename myout clear;

filename myin s3 "/my-dir/u1.txt" 
              awsconfig="/u/qz/.aws/config" 
              awscredentials="/u/qz/.aws/credentials" 
              encoding="utf-8";

data _null_;
   infile myin;
   input;
   put _infile_;
run;

filename myin clear;

Log Output

1          
2          filename myout s3 "/my-dir/u1.txt" 
                          awsconfig="/u/qz/.aws/config" 
                          awscredentials="/u/qz/.aws/credentials"
                        ! encoding="utf-8";
3          data _null_;
4             file myout;
5             put "create utf8 text file";
6             put "line1";
7             put "line2";
8             put "bye";
9          run;
NOTE: The file MYOUT is:
      Filename=/my-dir/u1.txt,
      File Size=38,
      Last Modified=Wed, 24 Aug 2022 16:11:48 GMT,
      Region=usstd,
      ETag=*******************,
      Accelerated=No
NOTE: 4 records were written to the file MYOUT.
      The minimum record length was 3.
      The maximum record length was 21.
NOTE: DATA statement used (Total process time):
      real time           0.24 seconds
      The SAS System      Wednesday, August 24, 2022 02:00:00 PM
      cpu time            0.07 seconds
10         filename myout clear;
NOTE: Fileref MYOUT has been deassigned.
13         filename myin s3 "/my-dir/u1.txt" 
                         awsconfig="/u/qz/.aws/config" 
                         awscredentials="/u/qz/.aws/credentials"
                       ! encoding="utf-8";
14         data _null_;
15            infile myin;
16            input;
17            put _infile_;
18         run;
NOTE: The infile MYIN is:
      Filename=/my-dir/u1.txt,
      File Size=38,
      Last Modified=Wed, 24 Aug 2022 18:00:11 GMT,
      Region=usstd,
      ETag=*******************,
      Accelerated=No
create utf8 text file
line1
line2
bye
NOTE: 4 records were read from the infile MYIN.
      The minimum record length was 3.
      The maximum record length was 21.
NOTE: DATA statement used (Total process time):
      real time           0.36 seconds
      cpu time            0.13 seconds
19         filename myin clear;
NOTE: Fileref MYIN has been deassigned.
Last updated: September 10, 2026