Log classes - Amazon CloudWatch Logs
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Log classes

CloudWatch Logs offers two classes of log groups:

  • The CloudWatch Logs Standard log class is a full-featured option for logs that require real-time monitoring or logs that you access frequently.

  • The CloudWatch Logs Infrequent Access log class is a new log class that you can use to cost-effectively consolidate your logs. This log class offers a subset of CloudWatch Logs capabilities including managed ingestion, storage, cross-account log analytics, and encryption with a lower ingestion price per GB. The Infrequent Access log class is ideal for ad-hoc querying and after-the-fact forensic analysis on infrequently accessed logs.

Note

For charges, the Standard and Infrequent Access log classes differ in ingestion costs only. Storage charges and CloudWatch Logs Insights charges are the same in each log class.

For more information about CloudWatch Logs pricing, see Amazon CloudWatch Pricing.

Important

After a log group is created, its log class can't be changed.

Supported features

The following table lists the features for each log class.

Feature Standard Infrequent Access

Fully managed log ingestion and storage

Yes ✓

Yes ✓

Cross-account features

Yes ✓

Yes ✓

Encryption with Amazon KMS

Yes ✓

Yes ✓

CloudWatch Logs Insights query commands

Yes ✓

Yes ✓ (Most commands– see Commands supported in log classes.)

CloudWatch Logs Insights discovered fields

Yes ✓

No

Natural language query assist

Yes ✓

No

CloudWatch Logs Anomaly Detection

Yes ✓

No

Compare to previous time range

Yes ✓

No

Subscription filters

Yes ✓

No

Export to Amazon S3

Yes ✓

No

GetLogEvents and FilterLogEvents API operations

Yes ✓

Not supported. Use CloudWatch Logs Insights to view log events stored in log groups in the Infrequent Access log class.

Metric filters

Yes ✓

No

Container Insights log ingestion

Yes ✓

No

Lambda Insights log ingestion

Yes ✓

No

Sensitive data protection with masking

Yes ✓

No

Embedded metrics format

Yes ✓

No