Home icon

Using Amazon S3 Server Access Logs with Amazon CloudWatch Logs

AWS Cloud Operations Blog



This article demonstrates how to use Amazon S3 server access logs with Amazon CloudWatch Logs for security monitoring and compliance auditing without building custom pipelines.

  • Enable S3 server access log ingestion using CloudWatch Telemetry Enablement Rules across your organization
  • Query logs with CloudWatch Logs Insights to detect unauthorized access attempts and unusual data transfer patterns
  • Create Metric Filters to emit CloudWatch metrics and trigger alarms on 403/404 spikes, 5xx errors, or anonymous access
  • Use Contributor Insights rules to identify top IPs and requesters generating errors or downloading data
  • Deploy a pre-built CloudFormation template for a complete Security, Compliance & Audit Dashboard
  • Centralize logs across multiple AWS accounts using CloudWatch Logs centralization rules
  • Transform logs to OCSF format using CloudWatch Pipelines for normalized security event data

CloudWatch provides a unified observability platform where S3 access logs are automatically structured and ready for querying, alerting, and compliance monitoring without additional infrastructure.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 29
2026
Amazon S3 server access logs now deliver to Amazon CloudWatch Logs and Amazon S3 Tables
Jun 29
2026
Query Amazon S3 access logs instantly with CloudWatch and S3 Tables
May 27
2026
Amazon S3 audit logging, Part 1: Analyzing server access logs with Amazon Athena for performance insights
Nov 12
2025
Amazon CloudWatch Logs now supports Network Load Balancer access logs

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.