View a markdown version of this page

Enable logging from AWS services - Amazon CloudWatch Logs

Enable logging from AWS services

Use the searchable catalog to find an AWS service and open its logging setup guide. For more information about the destinations and permissions models for each service, see Supported log destinations and permissions.

Many services publish logs only to CloudWatch Logs, but others use vended log delivery to send logs directly to Amazon Simple Storage Service or Amazon Data Firehose. Direct delivery is useful when your main requirement is long-term storage or processing in one of those destinations.

Even when you publish logs directly to Amazon S3 or Firehose, CloudWatch delivery charges apply. If you send logs to Amazon S3, then AWS_REGION-S3-Egress-Bytes charges appear in Cost Explorer or on your bill. If you send logs to Firehose, then AWS_REGION-FH-Egress-Bytes charges appear. For more information about vended logs pricing, see the Logs tab at Amazon CloudWatch Pricing.

Some services require additional permissions before they can deliver logs. Without these permissions, log delivery fails. In the comparison table, services that use the original permissions model are labeled Supported (V1 permissions). Services that use the current model are labeled Supported (V2 permissions). Each label links to the required policies.