Skip to contents

You can use Amazon CloudWatch Logs to monitor, store, and access your log files from EC2 instances, CloudTrail, and other sources. You can then retrieve the associated log data from CloudWatch Logs using the CloudWatch console. Alternatively, you can use CloudWatch Logs commands in the Amazon Web Services CLI, CloudWatch Logs API, or CloudWatch Logs SDK.

You can use CloudWatch Logs to:

  • Monitor logs from EC2 instances in real time: You can use CloudWatch Logs to monitor applications and systems using log data. For example, CloudWatch Logs can track the number of errors that occur in your application logs. Then, it can send you a notification whenever the rate of errors exceeds a threshold that you specify. CloudWatch Logs uses your log data for monitoring so no code changes are required. For example, you can monitor application logs for specific literal terms (such as "NullReferenceException"). You can also count the number of occurrences of a literal term at a particular position in log data (such as "404" status codes in an Apache access log). When the term you are searching for is found, CloudWatch Logs reports the data to a CloudWatch metric that you specify.

  • Monitor CloudTrail logged events: You can create alarms in CloudWatch and receive notifications of particular API activity as captured by CloudTrail. You can use the notification to perform troubleshooting.

  • Archive log data: You can use CloudWatch Logs to store your log data in highly durable storage. You can change the log retention setting so that any log events earlier than this setting are automatically deleted. The CloudWatch Logs agent helps to quickly send both rotated and non-rotated log data off of a host and into the log service. You can then access the raw log data when you need it.

Usage

cloudwatchlogs(
  config = list(),
  credentials = list(),
  endpoint = NULL,
  region = NULL
)

Arguments

config

Optional configuration of credentials, endpoint, and/or region.

  • credentials:

    • creds:

      • access_key_id: AWS access key ID

      • secret_access_key: AWS secret access key

      • session_token: AWS temporary session token

    • profile: The name of a profile to use. If not given, then the default profile is used.

    • anonymous: Set anonymous credentials.

  • endpoint: The complete URL to use for the constructed client.

  • region: The AWS Region used in instantiating the client.

  • close_connection: Immediately close all HTTP connections.

  • timeout: The time in seconds till a timeout exception is thrown when attempting to make a connection. The default is 60 seconds.

  • s3_force_path_style: Set this to true to force the request to use path-style addressing, i.e. http://s3.amazonaws.com/BUCKET/KEY.

  • sts_regional_endpoint: Set sts regional endpoint resolver to regional or legacy https://docs.aws.amazon.com/sdkref/latest/guide/feature-sts-regionalized-endpoints.html

credentials

Optional credentials shorthand for the config parameter

  • creds:

    • access_key_id: AWS access key ID

    • secret_access_key: AWS secret access key

    • session_token: AWS temporary session token

  • profile: The name of a profile to use. If not given, then the default profile is used.

  • anonymous: Set anonymous credentials.

endpoint

Optional shorthand for complete URL to use for the constructed client.

region

Optional shorthand for AWS Region used in instantiating the client.

Value

A client for the service. You can call the service's operations using syntax like svc$operation(...), where svc is the name you've assigned to the client. The available operations are listed in the Operations section.

Service syntax

svc <- cloudwatchlogs(
  config = list(
    credentials = list(
      creds = list(
        access_key_id = "string",
        secret_access_key = "string",
        session_token = "string"
      ),
      profile = "string",
      anonymous = "logical"
    ),
    endpoint = "string",
    region = "string",
    close_connection = "logical",
    timeout = "numeric",
    s3_force_path_style = "logical",
    sts_regional_endpoint = "string"
  ),
  credentials = list(
    creds = list(
      access_key_id = "string",
      secret_access_key = "string",
      session_token = "string"
    ),
    profile = "string",
    anonymous = "logical"
  ),
  endpoint = "string",
  region = "string"
)

Operations

associate_kms_keyAssociates the specified KMS key with either one log group in the account, or with all stored CloudWatch Logs query insights results in the account
associate_source_to_s3_table_integrationAssociates a data source with an S3 Table Integration for query access in the 'logs' namespace
cancel_export_taskCancels the specified export task
cancel_import_taskCancels an active import task and stops importing data from the CloudTrail Lake Event Data Store
create_deliveryCreates a delivery
create_export_taskCreates an export task so that you can efficiently export data from a log group to an Amazon S3 bucket
create_import_taskStarts an import from a data source to CloudWatch Log and creates a managed log group as the destination for the imported data
create_log_anomaly_detectorCreates an anomaly detector that regularly scans one or more log groups and look for patterns and anomalies in the logs
create_log_groupCreates a log group with the specified name
create_log_streamCreates a log stream for the specified log group
create_lookup_tableCreates a lookup table by uploading CSV data
create_scheduled_queryCreates a scheduled query that runs CloudWatch Logs Insights queries at regular intervals
delete_account_policyDeletes a CloudWatch Logs account policy
delete_data_protection_policyDeletes the data protection policy from the specified log group
delete_deliveryDeletes a delivery
delete_delivery_destinationDeletes a delivery destination
delete_delivery_destination_policyDeletes a delivery destination policy
delete_delivery_sourceDeletes a delivery source
delete_destinationDeletes the specified destination, and eventually disables all the subscription filters that publish to it
delete_index_policyDeletes a log-group level field index policy that was applied to a single log group
delete_integrationDeletes the integration between CloudWatch Logs and OpenSearch Service
delete_log_anomaly_detectorDeletes the specified CloudWatch Logs anomaly detector
delete_log_groupDeletes the specified log group and permanently deletes all the archived log events associated with the log group
delete_log_streamDeletes the specified log stream and permanently deletes all the archived log events associated with the log stream
delete_lookup_tableDeletes a lookup table permanently
delete_metric_filterDeletes the specified metric filter
delete_query_definitionDeletes a saved CloudWatch Logs Insights query definition
delete_resource_policyDeletes a resource policy from this account
delete_retention_policyDeletes the specified retention policy
delete_scheduled_queryDeletes a scheduled query and stops all future executions
delete_subscription_filterDeletes the specified subscription filter
delete_transformerDeletes the log transformer for the specified log group
describe_account_policiesReturns a list of all CloudWatch Logs account policies in the account
describe_configuration_templatesUse this operation to return the valid and default values that are used when creating delivery sources, delivery destinations, and deliveries
describe_deliveriesRetrieves a list of the deliveries that have been created in the account
describe_delivery_destinationsRetrieves a list of the delivery destinations that have been created in the account
describe_delivery_sourcesRetrieves a list of the delivery sources that have been created in the account
describe_destinationsLists all your destinations
describe_export_tasksLists the specified export tasks
describe_field_indexesReturns a list of custom and default field indexes which are discovered in log data
describe_import_task_batchesGets detailed information about the individual batches within an import task, including their status and any error messages
describe_import_tasksLists and describes import tasks, with optional filtering by import status and source ARN
describe_index_policiesReturns the field index policies of the specified log group
describe_log_groupsReturns information about log groups, including data sources that ingest into each log group
describe_log_streamsLists the log streams for the specified log group
describe_lookup_tablesRetrieves metadata about lookup tables in your account
describe_metric_filtersLists the specified metric filters
describe_queriesReturns a list of CloudWatch Logs Insights queries that are scheduled, running, or have been run recently in this account
describe_query_definitionsThis operation returns a paginated list of your saved CloudWatch Logs Insights query definitions
describe_resource_policiesLists the resource policies in this account
describe_subscription_filtersLists the subscription filters for the specified log group
disassociate_kms_keyDisassociates the specified KMS key from the specified log group or from all CloudWatch Logs Insights query results in the account
disassociate_source_from_s3_table_integrationDisassociates a data source from an S3 Table Integration, removing query access and deleting all associated data from the integration
filter_log_eventsLists log events from the specified log group
get_data_protection_policyReturns information about a log group data protection policy
get_deliveryReturns complete information about one logical delivery
get_delivery_destinationRetrieves complete information about one delivery destination
get_delivery_destination_policyRetrieves the delivery destination policy assigned to the delivery destination that you specify
get_delivery_sourceRetrieves complete information about one delivery source
get_integrationReturns information about one integration between CloudWatch Logs and OpenSearch Service
get_log_anomaly_detectorRetrieves information about the log anomaly detector that you specify
get_log_eventsLists log events from the specified log stream
get_log_fieldsDiscovers available fields for a specific data source and type
get_log_group_fieldsReturns a list of the fields that are included in log events in the specified log group
get_log_objectRetrieves a large logging object (LLO) and streams it back
get_log_recordRetrieves all of the fields and values of a single log event
get_lookup_tableRetrieves the full content of a lookup table, including the CSV data
get_query_resultsReturns the results from the specified query
get_scheduled_queryRetrieves details about a specific scheduled query, including its configuration, execution status, and metadata
get_scheduled_query_historyRetrieves the execution history of a scheduled query within a specified time range, including query results and destination processing status
get_transformerReturns the information about the log transformer associated with this log group
list_aggregate_log_group_summariesReturns an aggregate summary of all log groups in the Region grouped by specified data source characteristics
list_anomaliesReturns a list of anomalies that log anomaly detectors have found
list_integrationsReturns a list of integrations between CloudWatch Logs and other services in this account
list_log_anomaly_detectorsRetrieves a list of the log anomaly detectors in the account
list_log_groupsReturns a list of log groups in the Region in your account
list_log_groups_for_queryReturns a list of the log groups that were analyzed during a single CloudWatch Logs Insights query
list_scheduled_queriesLists all scheduled queries in your account and region
list_sources_for_s3_table_integrationReturns a list of data source associations for a specified S3 Table Integration, showing which data sources are currently associated for query access
list_tags_for_resourceDisplays the tags associated with a CloudWatch Logs resource
list_tags_log_groupThe ListTagsLogGroup operation is on the path to deprecation
put_account_policyCreates an account-level data protection policy, subscription filter policy, field index policy, transformer policy, or metric extraction policy that applies to all log groups, a subset of log groups, or a data source name and type combination in the account
put_bearer_token_authenticationEnables or disables bearer token authentication for the specified log group
put_data_protection_policyCreates a data protection policy for the specified log group
put_delivery_destinationCreates or updates a logical delivery destination
put_delivery_destination_policyCreates and assigns an IAM policy that grants permissions to CloudWatch Logs to deliver logs cross-account to a specified destination in this account
put_delivery_sourceCreates or updates a logical delivery source
put_destinationCreates or updates a destination
put_destination_policyCreates or updates an access policy associated with an existing destination
put_index_policyCreates or updates a field index policy for the specified log group
put_integrationCreates an integration between CloudWatch Logs and another service in this account
put_log_eventsUploads a batch of log events to the specified log stream
put_log_group_deletion_protectionEnables or disables deletion protection for the specified log group
put_metric_filterCreates or updates a metric filter and associates it with the specified log group
put_query_definitionCreates or updates a query definition for CloudWatch Logs Insights
put_resource_policyCreates or updates a resource policy allowing other Amazon Web Services services to put log events to this account, such as Amazon Route 53
put_retention_policySets the retention of the specified log group
put_subscription_filterCreates or updates a subscription filter and associates it with the specified log group
put_transformerCreates or updates a log transformer for a single log group
start_live_tailStarts a Live Tail streaming session for one or more log groups
start_queryStarts a query of one or more log groups or data sources using CloudWatch Logs Insights
stop_queryStops a CloudWatch Logs Insights query that is in progress
tag_log_groupThe TagLogGroup operation is on the path to deprecation
tag_resourceAssigns one or more tags (key-value pairs) to the specified CloudWatch Logs resource
test_metric_filterTests the filter pattern of a metric filter against a sample of log event messages
test_transformerUse this operation to test a log transformer
untag_log_groupThe UntagLogGroup operation is on the path to deprecation
untag_resourceRemoves one or more tags from the specified resource
update_anomalyUse this operation to suppress anomaly detection for a specified anomaly or pattern
update_delivery_configurationUse this operation to update the configuration of a delivery to change either the S3 path pattern or the format of the delivered logs
update_log_anomaly_detectorUpdates an existing log anomaly detector
update_lookup_tableUpdates an existing lookup table by replacing all of its CSV content
update_scheduled_queryUpdates an existing scheduled query with new configuration

Examples

if (FALSE) { # \dontrun{
svc <- cloudwatchlogs()
svc$associate_kms_key(
  Foo = 123
)
} # }