AWS
CloudWatch and Logs
Query CloudWatch log groups, read WAF logs, and let AI write the query for you.
CloudWatch is where AWS keeps logs and alarms. The CloudWatch screen has two tabs: Logs and Alarms.
Log sources
Rather than hunting through hundreds of log groups every time, save the ones you use as log sources. Each is a named shortcut to a log group in a region. Saved sources appear in the list for everyone who can see the project.
Querying
Logs are searched with CloudWatch Logs Insights, which has its own query language. A simple one:
fields @timestamp, @message
| filter @message like /error/
| sort @timestamp desc
| limit 50
Pick a time range and run it. Results appear as a table.
Let AI write the query
Rewrite query with AI turns an instruction into a query. Type what you want — "add a filter for 5xx errors in @message", "group by status code and count" — and it rewrites the query for you.
This is the feature to use if Logs Insights syntax is not something you intend to learn.
WAF logs
If you use AWS WAF (the web application firewall), its logs get a purpose-built table rather than raw JSON: which requests were blocked, by which rule, from where.
Explain with AI takes a blocked request and tells you in plain words why the firewall stopped it — which matters when it is blocking a real customer rather than an attacker. False positives on WAF rules are common, and unpicking them from raw JSON is genuinely unpleasant.
Alarms
The Alarms tab lists your CloudWatch alarms and their current state — OK, ALARM or INSUFFICIENT_DATA.
This tab is read-only. Creating and editing alarms happens in the AWS console. DevOps Agent does not send notifications for alarm state changes.
Dashboards
Saved CloudWatch dashboards can be registered and viewed here, next to your Grafana dashboards.
Costs
CloudWatch Logs Insights charges for the data each query scans. Narrow time ranges and specific log groups keep that small; "search everything for the last 30 days" can be surprisingly expensive.
Permissions
Needs logs:DescribeLogGroups, logs:StartQuery, logs:GetQueryResults and
cloudwatch:DescribeAlarms. See AWS permissions.
