Enable logging from AWS services
Use the searchable catalog to find an AWS service and open its logging setup guide. For more information about the destinations and permissions models for each service, see Supported log destinations and permissions.
Many services publish logs only to CloudWatch Logs, but others use vended log delivery to send logs directly to Amazon Simple Storage Service or Amazon Data Firehose. Direct delivery is useful when your main requirement is long-term storage or processing in one of those destinations.
Even when you publish logs directly to Amazon S3 or Firehose, CloudWatch delivery charges
apply. If you send logs to Amazon S3, then
charges appear in Cost
Explorer or on your bill. If you send logs to Firehose, then
AWS_REGION-S3-Egress-Bytes charges appear. For more
information about vended logs pricing, see the Logs tab at
Amazon CloudWatch PricingAWS_REGION-FH-Egress-Bytes
Some services require additional permissions before they can deliver logs. Without these permissions, log delivery fails. In the comparison table, services that use the original permissions model are labeled Supported (V1 permissions). Services that use the current model are labeled Supported (V2 permissions). Each label links to the required policies.
Amazon API Gateway
Application Load Balancer
AWS AppSync
Amazon Aurora MySQL
Amazon Bedrock AgentCore Gateway
Amazon Bedrock AgentCore Identity
Amazon Bedrock AgentCore Memory
Amazon Bedrock AgentCore Payments
Amazon Bedrock AgentCore Runtime
Amazon Bedrock AgentCore Tools
Amazon Bedrock Agents
Amazon Bedrock Knowledge Bases
Amazon Chime
Amazon CloudFront
AWS CloudHSM
AWS CloudTrail
CloudWatch Evidently
CloudWatch Internet Monitor
CloudWatch Logs Insights query execution logs
AWS CodeBuild
Amazon CodeWhisperer
Amazon Cognito
Amazon Connect
AWS DataSync
AWS DevOps Agent
EC2 Spot Instance
Amazon ECS
Amazon EKS Auto Mode
Amazon EKS Capability Logs
Amazon EKS Control Plane
AWS Elastic Beanstalk
Amazon ElastiCache (Redis OSS)
AWS Elemental MediaPackage
AWS Elemental MediaTailor
AWS Entity Resolution
Amazon EventBridge Event Buses
Amazon EventBridge Pipes
AWS Fargate
AWS Fault Injection Service
Amazon FinSpace
AWS Global Accelerator
AWS Glue
IAM Identity Center
AWS IoT
AWS IoT FleetWise
Amazon IVS Chat
AWS Lambda
Amazon Macie
AWS Mainframe Modernization
Amazon Managed Service for Prometheus
Amazon MQ
Amazon MSK
Amazon MSK Connect
AWS Network Firewall
AWS Network Firewall Proxy
Network Load Balancer
Amazon OpenSearch Ingestion
Amazon OpenSearch Service
AWS PCS
Amazon Q Business Connectors
Amazon Q Business Conversations
Amazon Q in Connect AI agents
Amazon Quick
Amazon RDS PostgreSQL
Amazon Route 53 Global Resolver
Amazon Route 53 Public DNS
Amazon Route 53 Resolver
AWS RTB Fabric
Amazon S3
Amazon SageMaker AI Events
Amazon SageMaker AI Worker Events
AWS Security Hub
AWS Security Hub CSPM
Amazon SES
AWS Shield Advanced
AWS Site-to-Site VPN
Amazon SNS
Amazon SNS Data Protection
AWS Step Functions
AWS Storage Gateway
AWS Transfer Family
AWS Verified Access
Amazon VPC Flow Logs
Amazon VPC Lattice
Amazon VPC Route Server
AWS WAF
Amazon WorkMail