Some AWS services can be configured to ship their logs to an S3 bucket, where can fetch those logs directly.

Best practices

The S3 API does not allow retrieval of object timestamps, so must collect logs in alphabetical order. Please keep these notes in mind when configuring logging.

  • Make the prefix as specific as possible
    The prefix is the part of your log path that remains constant across all logs. This can include folder structure and the beginning of the filename.

  • The log path after the prefix must come in alphabetical order
    We recommend starting the object name (after the prefix) with the Unix epoch time. The Unix epoch time is always increasing, ensuring we can always fetch your incoming logs.


You can add your buckets directly from by providing your S3 credentials and configuration.

Configure to fetch logs from an S3 bucket

Before you begin, you’ll need: s3:ListBucket and s3:GetObject permissions for the required S3 bucket

Add your S3 bucket information

To use the S3 fetcher, log into your account, and go to the S3 bucket log shipping page.

  1. Click + Add a bucket
  2. Select your preferred method of authentication - an IAM role or access keys.

The configuration wizard will open.

  1. Select the hosting region from the dropdown list.
  2. Provide the S3 bucket name
  3. Optional You have the option to add a prefix.
  4. Save your information.

S3 bucket configuration wizard fetches logs that are generated after configuring an S3 bucket. cannot fetch past logs retroactively.

Check for your logs

Give your logs some time to get from your system to ours, and then open Kibana.

If you still don’t see your logs, see log shipping troubleshooting.