Amazon CloudWatch Logs Insights empowers you to unlock greater value from your log data. You can query logs sent to CloudWatch in the AWS console, or start writing queries with aggregations, filters, and regular expressions for complete operational visibility. In addition, you can visualize time-series data, drill down into individual log events, and export query results to CloudWatch Dashboards.
Powered by generative AI, you can use natural language to query your logs (in preview) and quickly surface actionable insights, by asking questions such as “Show me the slowest Lambda functions”. You can describe in plain language the log data you need and CloudWatch automatically generates a tailored query, making it easy to analyze logs and surface insights faster no matter your level of expertise.
Powered by AI/ML, you can also speed up log investigation using CloudWatch Logs Anomaly Detection, which uses machine learning algorithms that have learned from decades of Amazon.com and AWS operational data at immense scale. With this feature, CloudWatch can recognize shared structures among log records, extract notable content and trends, and identify anomalies, helping you speed up MTTR without needing to set up configuration parameters.
With CloudWatch Logs Live Tail, you can interactively analyze streaming log data in real-time from a central view. Launch contextual queries to seamlessly transition from real-time log monitoring to deeper log analytics and accelerated incident investigation and resolution. Live Tail removes the need for custom solutions and consolidates critical logging capabilities to help you optimize time to detection and resolution.
The new integration between CloudWatch Logs and OpenSearch Service enables AWS customers to query and analyze logs in both CloudWatch and OpenSearch Service, providing access to the best of both solutions without the need for complex data pipelines and extract, transform, and load (ETL) operations. AWS customers can store logs centrally in CloudWatch Logs, while leveraging deep analytics powered by OpenSearch Service. CloudWatch Logs customers will get access to OpenSearch Service query capabilities (Piped Processing Language and SQL query support) and its automatic log dashboards for popular AWS vended logs (i.e., VPC, WAF, CloudTrail). OpenSearch Service customers will get access to CloudWatch Logs with no data duplication and management of associated pipelines. Using OpenSearch Service Discover, they can analyze operational logs data stored in CloudWatch Logs using OpenSearch Service SQL and Piped Processing Language, making it easier to perform complex queries and visualizations on their data without data movement.