Home icon

Query Amazon S3 access logs instantly with CloudWatch and S3 Tables

Storage Blog



This article explains how to deliver Amazon S3 server access logs directly to CloudWatch Logs for instant querying and optionally to S3 Tables in Apache Iceberg format for SQL analytics.

  • S3 access logs are parsed into structured fields upon ingestion and queryable within seconds via CloudWatch Logs Insights
  • Optional S3 Tables integration enables SQL queries in Amazon Athena without additional storage or maintenance costs
  • Organization-wide enablement via telemetry rules automatically configures logging across accounts and regions
  • Create metric filters and alarms to detect security issues like misconfigured IAM policies or credential leaks
  • Setup available through S3 console or AWS CLI with no ETL jobs, Glue crawlers, or infrastructure management required
  • Logs can be encrypted with AWS KMS keys and retention policies apply uniformly across CloudWatch and S3 Tables
  • Pricing based on CloudWatch Logs ingestion rates, storage, and query volume; S3 Tables storage and maintenance included at no extra charge

Organizations can now investigate access patterns, perform compliance audits, and analyze data usage without building custom forwarding pipelines or parsing infrastructure.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jul 2
2026
Using Amazon S3 Server Access Logs with Amazon CloudWatch Logs
Jun 29
2026
Amazon S3 server access logs now deliver to Amazon CloudWatch Logs and Amazon S3 Tables
Nov 12
2025
Amazon S3 Tables now support Amazon CloudWatch metrics
Mar 31
2026
Amazon CloudWatch Logs introduces lookup query command

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.