There are more AWS SDK examples available in the AWS Doc SDK Examples
CloudWatch Logs examples using AWS CLI
The following code examples show you how to perform actions and implement common scenarios by using the AWS Command Line Interface with CloudWatch Logs.
Actions are code excerpts from larger programs and must be run in context. While actions show you how to call individual service functions, you can see actions in context in their related scenarios.
Each example includes a link to the complete source code, where you can find instructions on how to set up and run the code in context.
Topics
Actions
The following code example shows how to use create-log-group.
- AWS CLI
-
The following command creates a log group named
my-logs:aws logs create-log-group --log-group-namemy-logs-
For API details, see CreateLogGroup
in AWS CLI Command Reference.
-
The following code example shows how to use create-log-stream.
- AWS CLI
-
The following command creates a log stream named
20150601in the log groupmy-logs:aws logs create-log-stream --log-group-namemy-logs--log-stream-name20150601-
For API details, see CreateLogStream
in AWS CLI Command Reference.
-
The following code example shows how to use delete-log-group.
- AWS CLI
-
The following command deletes a log group named
my-logs:aws logs delete-log-group --log-group-namemy-logs-
For API details, see DeleteLogGroup
in AWS CLI Command Reference.
-
The following code example shows how to use delete-log-stream.
- AWS CLI
-
The following command deletes a log stream named
20150531from a log group namedmy-logs:aws logs delete-log-stream --log-group-namemy-logs--log-stream-name20150531-
For API details, see DeleteLogStream
in AWS CLI Command Reference.
-
The following code example shows how to use delete-retention-policy.
- AWS CLI
-
The following command removes the retention policy that has previously been applied to a log group named
my-logs:aws logs delete-retention-policy --log-group-namemy-logs-
For API details, see DeleteRetentionPolicy
in AWS CLI Command Reference.
-
The following code example shows how to use describe-log-groups.
- AWS CLI
-
The following command describes a log group named
my-logs:aws logs describe-log-groups --log-group-name-prefixmy-logsOutput:
{ "logGroups": [ { "storedBytes": 0, "metricFilterCount": 0, "creationTime": 1433189500783, "logGroupName": "my-logs", "retentionInDays": 5, "arn": "arn:aws:logs:us-west-2:0123456789012:log-group:my-logs:*" } ] }-
For API details, see DescribeLogGroups
in AWS CLI Command Reference.
-
The following code example shows how to use describe-log-streams.
- AWS CLI
-
The following command shows all log streams starting with the prefix
2015in the log groupmy-logs:aws logs describe-log-streams --log-group-namemy-logs--log-stream-name-prefix2015Output:
{ "logStreams": [ { "creationTime": 1433189871774, "arn": "arn:aws:logs:us-west-2:0123456789012:log-group:my-logs:log-stream:20150531", "logStreamName": "20150531", "storedBytes": 0 }, { "creationTime": 1433189873898, "arn": "arn:aws:logs:us-west-2:0123456789012:log-group:my-logs:log-stream:20150601", "logStreamName": "20150601", "storedBytes": 0 } ] }-
For API details, see DescribeLogStreams
in AWS CLI Command Reference.
-
The following code example shows how to use get-log-events.
- AWS CLI
-
The following command retrieves log events from a log stream named
20150601in the log groupmy-logs:aws logs get-log-events --log-group-namemy-logs--log-stream-name20150601Output:
{ "nextForwardToken": "f/31961209122447488583055879464742346735121166569214640130", "events": [ { "ingestionTime": 1433190494190, "timestamp": 1433190184356, "message": "Example Event 1" }, { "ingestionTime": 1433190516679, "timestamp": 1433190184356, "message": "Example Event 1" }, { "ingestionTime": 1433190494190, "timestamp": 1433190184358, "message": "Example Event 2" } ], "nextBackwardToken": "b/31961209122358285602261756944988674324553373268216709120" }-
For API details, see GetLogEvents
in AWS CLI Command Reference.
-
The following code example shows how to use put-log-events.
- AWS CLI
-
The following command puts log events to a log stream named
20150601in the log groupmy-logs:aws logs put-log-events --log-group-namemy-logs--log-stream-name20150601--log-eventsfile://eventsOutput:
{ "nextSequenceToken": "49542672486831074009579604567656788214806863282469607346" }The above example reads a JSON array of events from a file named
eventsin the current directory:[ { "timestamp": 1433190184356, "message": "Example Event 1" }, { "timestamp": 1433190184358, "message": "Example Event 2" }, { "timestamp": 1433190184360, "message": "Example Event 3" } ]Each subsequent call requires the next sequence token provided by the previous call to be specified with the sequence token option:
aws logs put-log-events --log-group-namemy-logs--log-stream-name20150601--log-eventsfile://events2--sequence-token"49542672486831074009579604567656788214806863282469607346"Output:
{ "nextSequenceToken": "49542672486831074009579604567900991230369019956308219826" }-
For API details, see PutLogEvents
in AWS CLI Command Reference.
-
The following code example shows how to use put-retention-policy.
- AWS CLI
-
The following command adds a 5 day retention policy to a log group named
my-logs:aws logs put-retention-policy --log-group-namemy-logs--retention-in-days5-
For API details, see PutRetentionPolicy
in AWS CLI Command Reference.
-
The following code example shows how to use start-live-tail.
- AWS CLI
-
The following command starts a Live Tail session on a log group named
my-logs:aws logs start-live-tail --log-group-identifiersarn:aws:logs:us-east-1:111111222222:log-group:my-logsThe following command starts a Live Tail session on a log group named
my-logsin interactive mode:aws logs start-live-tail --log-group-identifiersarn:aws:logs:us-east-1:111111222222:log-group:my-logs--modeinteractiveIn interactive mode you can highlight as many as five terms in the tailed logs. The severity codes are highlighted by default. Press
hto enter the highlight mode and then type in the terms to be highlighted, one at a time, and press enter. Presscto clear the highlighted term(s). Presstto toggle formatting between JSON/Plain text. PressEscto exit the Live Tail session. Pressup/downkeys to scroll up or down between log events, useCtrl + u/Ctrl + dto scroll faster. Pressqto scroll to latest log events.-
For API details, see StartLiveTail
in AWS CLI Command Reference.
-