AWS CLI
AWS CLI (AWS Command Line Interface) is a command-line interface for working with AWS services that allows using Amazon CloudWatch API methods. For more information, see the DescribeLogGroups, DescribeLogStreams, GetLogEvents, and FilterLogEvents articles in the AWS documentation.
Using AWS CLI, you can work with logs: get events, event streams, and log groups.
Before you begin, configure AWS CLI.
Configure AWS CLI
1. Add a service user
Add a service user with permissions in the Projects scope and the role:
memberorlogs.adminfor read and write access to logs;logs.writerfor write access to logs;readerorlogs.viewerfor read-only access to logs.
Users can be added by the Account Owner or users with the iam.admin role.
2. Issue an S3 key to the user
Control panel users can issue S3 keys to themselves, but we recommend creating service users and issuing S3 keys to them.
Only the Account Owner or a user with the iam.admin role can issue S3 keys to other users. A service user cannot obtain an S3 key independently because they do not have access to the control panel — the Account Owner or iam.admin must issue a key to them.
You must create a separate key for each project. You can issue multiple keys for a single project.
-
In the control panel, in the top menu, click IAM.
-
Go to the section with the desired user type:
- Control panel users — for users with access to the control panel;
- Service users — for users with programmatic access without access to the control panel.
-
Open the user page → Access tab.
-
In the S3 keys block, click Add key.
-
Enter a key name.
-
Select the project for which the key will work.
-
Click Generate. Two values will be generated:
- Access key — Access Key ID, a key identifier;
- Secret key — Secret Access Key, a secret key.
-
Click Copy and save the key — it cannot be viewed after closing the window.
3. Install the client
Use the Install or update to the latest version of the AWS CLI guide in the Amazon documentation.
4. Configure AWS CLI settings
-
Open the CLI.
-
Open configuration mode:
aws configure -
Enter the
AWS Access Key ID— the value of the Access key field from the S3 key that you issued to the user, and press Enter. -
Enter the
AWS Secret Access Key— the value of the Secret key field from the S3 key that you issued to the user, and press Enter. -
Enter the
Default region name— the pool where the logs are located (for example,ru-9), and press Enter. -
Optional: enter the
Default output formator leave the value blank and press Enter. If you do not specify a value, the default output format will bejson. -
Settings will be saved in the configuration files:
- credentials in
.aws/credentials; - pool in
~/.aws/config.
- credentials in
-
In the
~/.aws/configfile, add theendpoint_urlparameter after theregionparameter:[default]endpoint_url = <log_endpoint>Specify
<log_endpoint>— the URL for accessing the Logs service API in the desired pool. The list of URLs can be found in the Logs subsection of the List of URLs guide.