Home icon

Use CloudWatch syslog and Log Alarms to give AWS DevOps Agent on-premises visibility

AWS Cloud Operations Blog



This article demonstrates how to use CloudWatch managed syslog ingestion and Log Alarms to monitor on-premises network devices and trigger AWS DevOps Agent investigations.

  • CloudWatch accepts syslog from firewalls, routers, switches, and Linux servers via VPC endpoints without requiring a collection tier
  • Supports RFC 5424, RFC 3164, Cisco FTD, and Cisco ASA syslog formats with automatic field extraction
  • CloudWatch Log Alarms query extracted fields and trigger alarms directly on log content without metric filters
  • Alarms publish to SNS topics, which invoke Lambda functions to sign and post events to AWS DevOps Agent webhooks
  • DevOps Agent investigates device failures by correlating syslog messages with application impact and identifying root causes
  • Solution uses VPC endpoints over AWS PrivateLink for secure, private connectivity from on-premises networks

This approach eliminates the need to build and maintain a syslog collection infrastructure while enabling automated incident investigation through DevOps Agent.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Sep 11
2026
Monitoring production agent lifecycle with AWS DevOps Agent and AgentCore Evaluations
Aug 28
2026
Amazon CloudWatch agent adds support for journald logs
Jun 23
2026
Amazon CloudWatch Logs supports managed syslog ingestion
May 26
2026
AgentWatch: Proactive AWS monitoring with ambient agents

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.