AWS CloudWatch monitoring for logs, metrics, alarms, and dashboards. Use when setting up monitoring, creating alarms, querying logs with Insights, configuring metric filters, building dashboards, or troubleshooting application issues.
Amazon CloudWatch provides monitoring and observability for AWS resources and applications. It collects metrics, logs, and events, enabling you to monitor, troubleshoot, and optimize your AWS environment.
Time-ordered data points published to CloudWatch. Key components:
AWS/Lambda)Invocations)FunctionName=MyFunc)Log data from AWS services and applications:
Automated actions based on metric thresholds:
AWS CLI:
# CPU utilization alarm for EC2
aws cloudwatch put-metric-alarm \
--alarm-name "HighCPU-i-1234567890abcdef0" \
--metric-name CPUUtilization \
--namespace AWS/EC2 \
--statistic Average \
--period 300 \
--threshold 80 \
--comparison-operator GreaterThanThreshold \
--evaluation-periods 2 \
--dimensions Name=InstanceId,Value=i-1234567890abcdef0 \
--alarm-actions arn:aws:sns:us-east-1:123456789012:alerts \
--ok-actions arn:aws:sns:us-east-1:123456789012:alertsboto3:
import boto3
cloudwatch = boto3.client('cloudwatch')
cloudwatch.put_metric_alarm(
AlarmName='HighCPU-i-1234567890abcdef0',
MetricName='CPUUtilization',
Namespace='AWS/EC2',
Statistic='Average',
Period=300,
Threshold=80.0,
ComparisonOperator='GreaterThanThreshold',
EvaluationPeriods=2,
Dimensions=[
{'Name': 'InstanceId', 'Value': 'i-1234567890abcdef0'}
],
AlarmActions=['arn:aws:sns:us-east-1:123456789012:alerts'],
OKActions=['arn:aws:sns:us-east-1:123456789012:alerts']
)aws cloudwatch put-metric-alarm \
--alarm-name "LambdaErrorRate-MyFunction" \
--metrics '[
{
"Id": "errors",
"MetricStat": {
"Metric": {
"Namespace": "AWS/Lambda",
"MetricName": "Errors",
"Dimensions": [{"Name": "FunctionName", "Value": "MyFunction"}]
},
"Period": 60,
"Stat": "Sum"
},
"ReturnData": false
},
{
"Id": "invocations",
"MetricStat": {
"Metric": {
"Namespace": "AWS/Lambda",
"MetricName": "Invocations",
"Dimensions": [{"Name": "FunctionName", "Value": "MyFunction"}]
},
"Period": 60,
"Stat": "Sum"
},
"ReturnData": false
},
{
"Id": "errorRate",
"Expression": "errors/invocations*100",
"Label": "Error Rate",
"ReturnData": true
}
]' \
--threshold 5 \
--comparison-operator GreaterThanThreshold \
--evaluation-periods 3 \
--alarm-actions arn:aws:sns:us-east-1:123456789012:alerts# Find errors in Lambda logs
aws logs start-query \
--log-group-name /aws/lambda/MyFunction \
--start-time $(date -d '1 hour ago' +%s) \
--end-time $(date +%s) \
--query-string '
fields @timestamp, @message
| filter @message like /ERROR/
| sort @timestamp desc
| limit 50
'
# Get query results
aws logs get-query-results --query-id <query-id>boto3:
import boto3
import time
logs = boto3.client('logs')
# Start query
response = logs.start_query(
logGroupName='/aws/lambda/MyFunction',
startTime=int(time.time()) - 3600,
endTime=int(time.time()),
queryString='''
fields @timestamp, @message
| filter @message like /ERROR/
| sort @timestamp desc
| limit 50
'''
)
query_id = response['queryId']
# Wait for results
while True:
result = logs.get_query_results(queryId=query_id)
if result['status'] == 'Complete':
break
time.sleep(1)
for row in result['results']:
print(row)Extract metrics from log patterns:
# Create metric filter for error count
aws logs put-metric-filter \
--log-group-name /aws/lambda/MyFunction \
--filter-name ErrorCount \
--filter-pattern "ERROR" \
--metric-transformations \
metricName=ErrorCount,metricNamespace=MyApp,metricValue=1,defaultValue=0Alarm directly on a Logs Insights query (no metric filter needed). CloudWatch creates and manages the underlying scheduled query. The ScheduledQueryRoleARN role must trust logs.amazonaws.com and allow logs:StartQuery and logs:GetQueryResults on the log group ARNs, plus logs:StopQuery and logs:DescribeLogGroups on "Resource": "*" (these two support no resource-level permissions, so a log-group-scoped statement never matches them).
# ALARM when >100 errors in 3 of the last 5 query runs
aws cloudwatch put-log-alarm \
--alarm-name "HighErrorCount" \
--comparison-operator GreaterThanThreshold \
--threshold 100 \
--query-results-to-evaluate 5 \
--query-results-to-alarm 3 \
--treat-missing-data notBreaching \
--alarm-actions arn:aws:sns:us-east-1:123456789012:alerts \
--scheduled-query-configuration '{
"QueryString": "fields @timestamp, @message | filter @message like /ERROR/",
"LogGroupIdentifiers": ["/aws/lambda/MyFunction"],
"ScheduledQueryRoleARN": "arn:aws:iam::123456789012:role/ScheduledQueryRole",
"AggregationExpression": "count(*)",
"ScheduleConfiguration": {
"ScheduleExpression": "rate(10 minutes)",
"StartTimeOffset": 600
}
}'
# Log alarms are omitted from describe-alarms unless requested
aws cloudwatch describe-alarms --alarm-types LogAlarmimport boto3
cloudwatch = boto3.client('cloudwatch')
cloudwatch.put_metric_data(
Namespace='MyApp',
MetricData=[
{
'MetricName': 'OrdersProcessed',
'Value': 1,
'Unit': 'Count',
'Dimensions': [
{'Name': 'Environment', 'Value': 'Production'},
{'Name': 'OrderType', 'Value': 'Standard'}
]
}
]
)cat > dashboard.json << 'EOF'
{
"widgets": [
{
"type": "metric",
"x": 0, "y": 0, "width": 12, "height": 6,
"properties": {
"title": "Lambda Invocations",
"metrics": [
["AWS/Lambda", "Invocations", "FunctionName", "MyFunction"]
],
"period": 60,
"stat": "Sum",
"region": "us-east-1"
}
},
{
"type": "log",
"x": 12, "y": 0, "width": 12, "height": 6,
"properties": {
"title": "Recent Errors",
"query": "SOURCE '/aws/lambda/MyFunction' | filter @message like /ERROR/ | limit 20",
"region": "us-east-1"
}
}
]
}
EOF
aws cloudwatch put-dashboard \
--dashboard-name MyAppDashboard \
--dashboard-body file://dashboard.json| Command | Description |
|---|---|
aws cloudwatch put-metric-data | Publish custom metrics |
aws cloudwatch get-metric-data | Retrieve metric values |
aws cloudwatch get-metric-statistics | Get aggregated statistics |
aws cloudwatch list-metrics | List available metrics |
| Command | Description |
|---|---|
aws cloudwatch put-metric-alarm | Create or update alarm |
aws cloudwatch put-log-alarm | Create or update log query alarm |
aws cloudwatch describe-alarms | List alarms (--alarm-types LogAlarm for log alarms) |
aws cloudwatch describe-alarm-contributors | Show breaching contributors of a multi-contributor alarm |
aws cloudwatch put-alarm-mute-rule | Create or update scheduled mute window |
aws cloudwatch list-alarm-mute-rules | List mute rules (--statuses SCHEDULED ACTIVE EXPIRED) |
aws cloudwatch delete-alarm-mute-rule | Delete mute rule (unmutes immediately) |
aws cloudwatch set-alarm-state | Manually set alarm state |
aws cloudwatch delete-alarms | Delete alarms |
| Command | Description |
|---|---|
aws logs create-log-group | Create log group |
aws logs put-log-events | Write log events |
aws logs filter-log-events | Search log events |
aws logs start-query | Start Insights query |
aws logs put-metric-filter | Create metric filter |
aws logs put-retention-policy | Set log retention |
--treat-missing-data notBreaching for sparse errors, breaching to detect logs that stop arriving--warm-up-configuration on alarms created alongside new resources (1-2880 min) to avoid noise before metrics publish--evaluation-window WallClockWindow={Timezone=...} for daily/weekly batch or backup alarms; keep the default sliding window for Auto Scalingdisable-alarm-actions; enable-alarm-actions does not unmute an active mute ruleCauses:
Debug:
# List metrics for a namespace
aws cloudwatch list-metrics \
--namespace AWS/Lambda \
--dimensions Name=FunctionName,Value=MyFunctionCauses:
OnlyStartEvaluatingAfterWarmUpPeriodEnds=true)EvaluationState = EVALUATION_ERROR, see StateReason), or ingestion lag (shift window back with EndTimeOffset)Debug:
# Check if metric has data
aws cloudwatch get-metric-statistics \
--namespace AWS/Lambda \
--metric-name Invocations \
--dimensions Name=FunctionName,Value=MyFunction \
--start-time $(date -d '1 hour ago' -u +%Y-%m-%dT%H:%M:%SZ) \
--end-time $(date -u +%Y-%m-%dT%H:%M:%SZ) \
--period 60 \
--statistics Sum
# Log alarm: check evaluation state and reason
aws cloudwatch describe-alarms --alarm-types LogAlarm --alarm-names HighErrorCount \
--query 'LogAlarms[].[StateValue,EvaluationState,StateReason]'Causes:
Debug:
# Check log streams
aws logs describe-log-streams \
--log-group-name /aws/lambda/MyFunction \
--order-by LastEventTime \
--descending \
--limit 5Check usage:
# Get PutLogEvents usage
aws cloudwatch get-metric-statistics \
--namespace AWS/Logs \
--metric-name IncomingBytes \
--dimensions Name=LogGroupName,Value=/aws/lambda/MyFunction \
--start-time $(date -d '7 days ago' -u +%Y-%m-%dT%H:%M:%SZ) \
--end-time $(date -u +%Y-%m-%dT%H:%M:%SZ) \
--period 86400 \
--statistics Sume786d25
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.