- Support
- Integrations
- CloudWatch Logs
CloudWatch Logs
AWS integration · 28 node(s).
00Overview
Manage Amazon CloudWatch Logs end to end from a flow — create and delete log groups and streams, write log events, read them back from a stream, and search across streams by pattern and time range. Run Logs Insights queries, set retention, and export a log group to an S3 bucket, plus manage metric filters, subscription filters, saved query definitions and data protection policies. Every action runs against the AWS region and account whose credentials you give the node.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting CloudWatch Logs
- Pick an Authentication method. Access Keys uses your own IAM key pair; Assume Role (cross-account) lets Flomation call your account through an IAM role you control; Managed Role (Credential) reuses an AWS credential already stored in Flomation.
- For Access Keys, open the AWS IAM console (console.aws.amazon.com → IAM) → Users → your user → Security credentials → Create access key, and copy the Access key ID and Secret access key — the secret is shown only once. Grant the user the CloudWatch Logs permissions you plan to automate (for example the
logs:*actions you need). Paste the values into AWS Access Key and AWS Secret Key, and fill Session Token (optional) only when you are using temporary STS credentials. - For Assume Role (cross-account), create an IAM role in your account whose trust policy allows Flomation's principal to call
sts:AssumeRole, attach the CloudWatch Logs permissions to that role, and paste its ARN into Role ARN to Assume. If the role's trust policy sets an External ID, put the matching value in Assume Role External ID (optional). - For Managed Role (Credential), choose your pre-configured AWS credential in the AWS Role Credential field.
- Set Region to the AWS region that holds the log groups (for example
eu-west-2) — CloudWatch Logs data is region-scoped, so the region must match where the logs live. - Store the secret access key as a Flomation environment secret (e.g.
cloudwatchlogs_secret) and select it in the node's AWS Secret Key field rather than typing it inline.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Required | Access Keys, Assume Role (cross-account), Managed Role (Credential) |
| AWS Access Key | secret | Required | |
| AWS Secret Key | secret | Required | |
| Session Token (optional) | secret | ||
| AWS Role Credential | credential | Required |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Cancel
AWS CloudWatch Cancel Export Task
aws/cloudwatchlogs/cancel_export_task · Action
Cancel a pending or running log export task.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Task ID | string | Required |
Returns: tool_result, task_id
03Create
AWS CloudWatch Create Export Task
aws/cloudwatchlogs/create_export_task · Action
Export a log group's events to an S3 bucket over a time range.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Destination S3 Bucket | string | Required | my-export-bucket |
| Destination Prefix (optional) | string | exportedlogs | |
| From (RFC3339) | string | Required | 2026-07-01T00:00:00Z |
| To (RFC3339) | string | Required | 2026-07-22T00:00:00Z |
| Task Name (optional) | string | july-export | |
| Log Stream Name Prefix (optional) | string |
Returns: tool_result, task_id
AWS CloudWatch Logs Create Log Group
aws/cloudwatchlogs/create_log_group · Action
Create a CloudWatch Logs log group, optionally KMS-encrypted and tagged.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/my-app |
| KMS Key ARN (optional) | string | arn:aws:kms:...:key/... | |
| Tags | key_value_array |
Returns: tool_result
AWS CloudWatch Logs Create Log Stream
aws/cloudwatchlogs/create_log_stream · Action
Create a log stream inside an existing CloudWatch Logs log group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/my-app |
| Log Stream Name | string | Required | 2026/07/22 |
Returns: tool_result
04Delete
AWS CloudWatch Delete Data Protection Policy
aws/cloudwatchlogs/delete_data_protection_policy · Action
Remove the data protection policy attached to a log group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name or ARN | string | Required | /flomation/app |
Returns: tool_result, log_group_identifier
AWS CloudWatch Logs Delete Log Group
aws/cloudwatchlogs/delete_log_group · Action
Delete a CloudWatch Logs log group and all its log streams and events.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/my-app |
Returns: tool_result
AWS CloudWatch Logs Delete Log Stream
aws/cloudwatchlogs/delete_log_stream · Action
Delete a CloudWatch Logs log stream and all of its log events.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Log Stream Name | string | Required | 2026/07/22/[$LATEST]abc123 |
Returns: tool_result, log_stream_name
AWS CloudWatch Logs Delete Metric Filter
aws/cloudwatchlogs/delete_metric_filter · Action
Delete a metric filter from a CloudWatch Logs log group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Filter Name | string | Required | ErrorCount |
Returns: tool_result, filter_name
AWS CloudWatch Delete Query Definition
aws/cloudwatchlogs/delete_query_definition · Action
Delete a saved Logs Insights query definition by ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Query Definition ID | string | Required |
Returns: tool_result, success
AWS CloudWatch Logs Delete Subscription Filter
aws/cloudwatchlogs/delete_subscription_filter · Action
Delete a subscription filter from a CloudWatch Logs log group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Filter Name | string | Required | ship-logs |
Returns: tool_result, filter_name
05Describe
AWS CloudWatch Describe Export Tasks
aws/cloudwatchlogs/describe_export_tasks · Action
List log export tasks, optionally filtered by task ID or status.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Task ID (optional) | string | ||
| Status Code (optional) | string | choices: Cancelled, Completed, Failed, Pending, Pending Cancel, Running |
Returns: tool_result, export_tasks, count
AWS CloudWatch Logs Describe Log Groups
aws/cloudwatchlogs/describe_log_groups · Action
List CloudWatch Logs log groups, optionally filtered by a name prefix.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name Prefix (optional) | string | /flomation/ |
Returns: tool_result, log_groups, count
AWS CloudWatch Logs Describe Log Streams
aws/cloudwatchlogs/describe_log_streams · Action
List the log streams within a CloudWatch Logs log group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/my-app |
| Log Stream Name Prefix (optional) | string | 2026/07 | |
| Order By (optional) | string | choices: Log Stream Name, Last Event Time |
Returns: tool_result, log_streams, count
AWS CloudWatch Logs Describe Metric Filters
aws/cloudwatchlogs/describe_metric_filters · Action
List CloudWatch Logs metric filters, optionally scoped to a log group or name prefix.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name (optional) | string | /flomation/app | |
| Filter Name Prefix (optional) | string | Error |
Returns: tool_result, metric_filters, count
AWS CloudWatch Describe Query Definitions
aws/cloudwatchlogs/describe_query_definitions · Action
List saved Logs Insights query definitions, optionally filtered by name prefix.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Name Prefix (optional) | string |
Returns: tool_result, query_definitions, count
AWS CloudWatch Logs Describe Subscription Filters
aws/cloudwatchlogs/describe_subscription_filters · Action
List the subscription filters attached to a CloudWatch Logs log group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Filter Name Prefix (optional) | string | ship-logs |
Returns: tool_result, subscription_filters, count
06Filter
AWS CloudWatch Filter Log Events
aws/cloudwatchlogs/filter_log_events · Action
Search CloudWatch Logs across streams by filter pattern and time range.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Filter Pattern (optional) | string | ERROR | |
| Start Time (RFC3339, optional) | string | 2026-07-22T00:00:00Z | |
| End Time (RFC3339, optional) | string | 2026-07-22T23:59:59Z | |
| Per-page Limit (optional) | integer | 100 |
Returns: tool_result, events, count
07Get
AWS CloudWatch Get Data Protection Policy
aws/cloudwatchlogs/get_data_protection_policy · Action
Retrieve the data protection policy attached to a log group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name or ARN | string | Required | /flomation/app |
Returns: tool_result, policy_document, last_updated
AWS CloudWatch Get Log Events
aws/cloudwatchlogs/get_log_events · Action
Read log events from a CloudWatch Logs stream, optionally by time range.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Log Stream Name | string | Required | my-stream |
| Start Time (RFC3339, optional) | string | 2026-07-22T00:00:00Z | |
| End Time (RFC3339, optional) | string | 2026-07-22T23:59:59Z | |
| Limit (optional) | integer | 100 | |
| Oldest First (optional) | boolean |
Returns: tool_result, events, count
AWS CloudWatch Get Query Results
aws/cloudwatchlogs/get_query_results · Action
Fetch the results and status of a CloudWatch Logs Insights query.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Query ID | string | Required | From Start Query |
Returns: tool_result, status, results, statistics
08Put
AWS CloudWatch Put Data Protection Policy
aws/cloudwatchlogs/put_data_protection_policy · Action
Attach a data protection policy that masks sensitive data in a log group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name or ARN | string | Required | /flomation/app |
| Policy Document (JSON) | string | Required | {"Name":"MaskPII","Version":"2021-06-01","Statement":[...]} |
Returns: tool_result, log_group_identifier
AWS CloudWatch Put Log Events
aws/cloudwatchlogs/put_log_events · Action
Write one or more log events to a CloudWatch Logs stream.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Log Stream Name | string | Required | my-stream |
| Messages | string | Required | A plain message, or a JSON array of {"timestamp","message"} |
Returns: tool_result, next_sequence_token
AWS CloudWatch Put Metric Filter
aws/cloudwatchlogs/put_metric_filter · Action
Create or update a metric filter that emits CloudWatch metrics from log events.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Filter Name | string | Required | ErrorCount |
| Filter Pattern | string | Required | ERROR |
| Metric Transformations (JSON array) | string | Required | [{"metricName":"ErrorCount","metricNamespace":"Flomation","metricValue":"1"}] |
Returns: tool_result, filter_name
AWS CloudWatch Put Query Definition
aws/cloudwatchlogs/put_query_definition · Action
Create or update a saved CloudWatch Logs Insights query definition.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Query Name | string | Required | Errors by service |
| Query String | string | Required | fields @timestamp, @message | filter @message like /ERROR/ |
| Log Group Names (comma-separated, optional) | string | /flomation/app,/flomation/api |
Returns: tool_result, query_definition_id
AWS CloudWatch Logs Put Retention Policy
aws/cloudwatchlogs/put_retention_policy · Action
Set how many days a CloudWatch Logs log group retains its events.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/my-app |
| Retention (days) | integer | Required | 30 |
Returns: tool_result
AWS CloudWatch Put Subscription Filter
aws/cloudwatchlogs/put_subscription_filter · Action
Stream matching log events from a log group to a destination (Lambda, Kinesis, Firehose).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Filter Name | string | Required | ForwardErrors |
| Filter Pattern | string | Required | ERROR (empty matches all) |
| Destination ARN | string | Required | arn:aws:lambda:eu-west-2:...:function:... |
| Role ARN (optional) | string | arn:aws:iam::...:role/... |
Returns: tool_result, filter_name
09Start
AWS CloudWatch Start Query
aws/cloudwatchlogs/start_query · Action
Start a CloudWatch Logs Insights query over a log group and time range.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Log Group Name | string | Required | /flomation/app |
| Query String | string | Required | fields @timestamp, @message | sort @timestamp desc | limit 20 |
| Start Time (RFC3339) | string | Required | 2026-07-22T00:00:00Z |
| End Time (RFC3339) | string | Required | 2026-07-22T23:59:59Z |
| Limit (optional) | integer | 1000 |
Returns: tool_result, query_id
10Stop
AWS CloudWatch Logs Stop Query
aws/cloudwatchlogs/stop_query · Action
Stop a running CloudWatch Logs Insights query by its query ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Query ID | string | Required | 12ab3456-12ab-123a-789e-1234567890ab |
Returns: tool_result, success
11Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- Logs Insights queries run asynchronously: Start Query returns only a query ID, so a later Get Query Results step must poll until the reported status is Complete before the rows are available.
- Filter Log Events returns at most 200 matched events per run regardless of the per-page Limit you set, so narrow the time range or tighten the filter pattern rather than expecting an entire log group in one call.
- Retention (days) accepts only the fixed set of values CloudWatch Logs supports — such as 1, 3, 5, 7, 14, 30, 60, 90, 365 and so on up to 3653 — and any other number is rejected.
- Put Log Events timestamps are epoch milliseconds; when you pass a JSON array of events, supply millisecond values, and any entry left without a timestamp is stamped with the current time.
- AWS allows only one active log export task per account at a time, so start a new Create Export Task only after the previous export has finished.