Amazon CloudWatch Logs supports managed syslog ingestion
News
Amazon CloudWatch Logs now supports managed syslog ingestion, enabling customers to send syslog messages from firewalls, routers, switches, and Linux servers directly into CloudWatch Logs.
- Send syslog over TCP, TCP+TLS, or UDP to a VPC endpoint without installing agents
- Supports RFC 5424, RFC 3164, and Cisco FTD/ASA syslog formats
- Automatically parses syslog messages and extracts structured fields like facility, severity, hostname, and application name
- Query logs by severity or hostname using Logs Analytics for security investigations
- Available in all commercial AWS Regions except Middle East (UAE), Bahrain, and Tel Aviv
This feature centralizes infrastructure log visibility and simplifies operational workflows by eliminating the need for custom parsing and log collection agents.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Mar 17
2026
2026
Amazon CloudWatch Logs now supports log ingestion using HTTP-based protocol
Jul 24
2026
2026
Amazon CloudWatch Logs now supports Application Load Balancer logs
Nov 26
2025
2025
Amazon CloudWatch now supports deletion protection for logs
Nov 12
2025
2025
Amazon CloudWatch Logs now supports Network Load Balancer access logs
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.