Using Amazon S3 Server Access Logs with Amazon CloudWatch Logs
AWS Cloud Operations Blog
This article demonstrates how to use Amazon S3 server access logs with Amazon CloudWatch Logs for security monitoring and compliance auditing without building custom pipelines.
- Enable S3 server access log ingestion using CloudWatch Telemetry Enablement Rules across your organization
- Query logs with CloudWatch Logs Insights to detect unauthorized access attempts and unusual data transfer patterns
- Create Metric Filters to emit CloudWatch metrics and trigger alarms on 403/404 spikes, 5xx errors, or anonymous access
- Use Contributor Insights rules to identify top IPs and requesters generating errors or downloading data
- Deploy a pre-built CloudFormation template for a complete Security, Compliance & Audit Dashboard
- Centralize logs across multiple AWS accounts using CloudWatch Logs centralization rules
- Transform logs to OCSF format using CloudWatch Pipelines for normalized security event data
CloudWatch provides a unified observability platform where S3 access logs are automatically structured and ready for querying, alerting, and compliance monitoring without additional infrastructure.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2026
2026
2025
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.