---
title: "AWS logs: Firehose | Grafana Labs"
description: "Collect high-volume CloudWatch logs using Amazon Data Firehose."
---

> For a curated documentation index, see [llms.txt](/llms.txt). For the complete documentation index, see [llms-full.txt](/llms-full.txt).

# AWS logs: Firehose

[![AWS logs Firehose architecture: CloudWatch Logs to Amazon Data Firehose to Grafana Cloud Logs](cp-olly-aws-logs-firehose-light.svg)](cp-olly-aws-logs-firehose-light.svg "AWS logs Firehose architecture: CloudWatch Logs to Amazon Data Firehose to Grafana Cloud Logs")

**Complexity:** Moderate | **Infrastructure:** Managed | **Latency:** Buffered (60s default)

You configure a subscription filter on your CloudWatch log group that sends logs to an Amazon Data Firehose stream. The stream batches the logs and delivers them to Grafana Cloud, with built-in retry and error handling. AWS handles the scaling.

## CloudWatch logs collected with Firehose

| Log type              | Source                 | Key insights               |
|-----------------------|------------------------|----------------------------|
| **CloudWatch Logs**   | Applications, services | Application events, errors |
| **RDS Instance Logs** | Database instances     | Query logs, slow queries   |
| **VPC Flow Logs**     | Network interfaces     | Network traffic, security  |

## Considerations

- High-throughput streaming with automatic scaling
- Automatic retry and error handling
- Native CloudWatch integration
- Cost-effective for high log volumes
- Buffered delivery; the reference configuration uses a 60-second buffer
- Both Firehose and Lambda filter with a CloudWatch subscription filter pattern; Lambda additionally supports relabeling
- IAM role setup required, plus Amazon Data Firehose usage cost

## Documentation

View the [AWS Firehose logs](/docs/grafana-cloud/monitor-infrastructure/monitor-cloud-provider/aws/logs/firehose-logs/) documentation.
