View a markdown version of this page

Enable logging from Amazon services - Amazon CloudWatch Logs
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Enable logging from Amazon services

Use the searchable catalog to find an Amazon service and open its logging setup guide. For more information about the destinations and permissions models for each service, see Supported log destinations and permissions.

Many services publish logs only to CloudWatch Logs, but others use vended log delivery to send logs directly to Amazon Simple Storage Service or Amazon Data Firehose. Direct delivery is useful when your main requirement is long-term storage or processing in one of those destinations.

Even when you publish logs directly to Amazon S3 or Firehose, CloudWatch delivery charges apply. If you send logs to Amazon S3, then AWS_REGION-S3-Egress-Bytes charges appear in Cost Explorer or on your bill. If you send logs to Firehose, then AWS_REGION-FH-Egress-Bytes charges appear. For more information about vended logs pricing, see the Logs tab at Amazon CloudWatch Pricing.

Some services require additional permissions before they can deliver logs. Without these permissions, log delivery fails. In the comparison table, services that use the original permissions model are labeled Supported (V1 permissions). Services that use the current model are labeled Supported (V2 permissions). Each label links to the required policies.