Home icon

Create a customizable cross-company log lake, Part II: Build and add Amazon Bedrock

Big Data Blog



This article explains how to build Log Lake, a customizable data lake for compliance and security auditing, and how to integrate Amazon Bedrock model invocation logs for reviewing AI agent actions.

  • Log Lake joins CloudTrail and CloudWatch logs to audit employee Session Manager activity at scale
  • Architecture uses separate raw (JSON) and readready (ORC) tables for write and read optimization
  • AddAPart Lambda functions automatically associate incoming files with Hive table partitions via SQS
  • AWS Glue jobs transform raw JSON files into optimized ORC columnar format for faster queries
  • Amazon Bedrock model invocation logs can be added as a new data source for agent oversight
  • Log Lake Looker uses Claude AI to query logs naturally without writing SQL
  • Multiple security layers protect against prompt injection and unauthorized data access
  • Solution includes deployment scripts and demo data in GitHub repository

Log Lake provides a scalable, customizable framework for compliance investigations, forensic analysis, and auditing across multiple AWS services and AI workloads.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jan 29
2026
Amazon Bedrock now supports server-side custom tools using the Responses API
Feb 5
2026
Building a .NET Log Analysis System using Amazon Bedrock
Jan 21
2026
How bunq handles 97% of support with Amazon Bedrock
Jan 22
2026
Amazon Bedrock AgentCore Browser now supports custom browser extensions

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.