1. Support
  2. Integrations
  3. CloudWatch Logs
AWS 28 nodes

CloudWatch Logs

AWS integration · 28 node(s).

00Overview

Manage Amazon CloudWatch Logs end to end from a flow — create and delete log groups and streams, write log events, read them back from a stream, and search across streams by pattern and time range. Run Logs Insights queries, set retention, and export a log group to an S3 bucket, plus manage metric filters, subscription filters, saved query definitions and data protection policies. Every action runs against the AWS region and account whose credentials you give the node.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting CloudWatch Logs

  1. Pick an Authentication method. Access Keys uses your own IAM key pair; Assume Role (cross-account) lets Flomation call your account through an IAM role you control; Managed Role (Credential) reuses an AWS credential already stored in Flomation.
  2. For Access Keys, open the AWS IAM console (console.aws.amazon.com → IAM) → Users → your user → Security credentials → Create access key, and copy the Access key ID and Secret access key — the secret is shown only once. Grant the user the CloudWatch Logs permissions you plan to automate (for example the logs:* actions you need). Paste the values into AWS Access Key and AWS Secret Key, and fill Session Token (optional) only when you are using temporary STS credentials.
  3. For Assume Role (cross-account), create an IAM role in your account whose trust policy allows Flomation's principal to call sts:AssumeRole, attach the CloudWatch Logs permissions to that role, and paste its ARN into Role ARN to Assume. If the role's trust policy sets an External ID, put the matching value in Assume Role External ID (optional).
  4. For Managed Role (Credential), choose your pre-configured AWS credential in the AWS Role Credential field.
  5. Set Region to the AWS region that holds the log groups (for example eu-west-2) — CloudWatch Logs data is region-scoped, so the region must match where the logs live.
  6. Store the secret access key as a Flomation environment secret (e.g. cloudwatchlogs_secret) and select it in the node's AWS Secret Key field rather than typing it inline.
FieldTypeDetails
AuthenticationstringRequiredAccess Keys, Assume Role (cross-account), Managed Role (Credential)
AWS Access KeysecretRequired
AWS Secret KeysecretRequired
Session Token (optional)secret
AWS Role CredentialcredentialRequired
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Cancel

AWS CloudWatch Cancel Export Task

aws/cloudwatchlogs/cancel_export_task · Action

Cancel a pending or running log export task.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Task IDstringRequired

Returns: tool_result, task_id

03Create

AWS CloudWatch Create Export Task

aws/cloudwatchlogs/create_export_task · Action

Export a log group's events to an S3 bucket over a time range.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Destination S3 BucketstringRequiredmy-export-bucket
Destination Prefix (optional)stringexportedlogs
From (RFC3339)stringRequired2026-07-01T00:00:00Z
To (RFC3339)stringRequired2026-07-22T00:00:00Z
Task Name (optional)stringjuly-export
Log Stream Name Prefix (optional)string

Returns: tool_result, task_id

AWS CloudWatch Logs Create Log Group

aws/cloudwatchlogs/create_log_group · Action

Create a CloudWatch Logs log group, optionally KMS-encrypted and tagged.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/my-app
KMS Key ARN (optional)stringarn:aws:kms:...:key/...
Tagskey_value_array

Returns: tool_result

AWS CloudWatch Logs Create Log Stream

aws/cloudwatchlogs/create_log_stream · Action

Create a log stream inside an existing CloudWatch Logs log group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/my-app
Log Stream NamestringRequired2026/07/22

Returns: tool_result

04Delete

AWS CloudWatch Delete Data Protection Policy

aws/cloudwatchlogs/delete_data_protection_policy · Action

Remove the data protection policy attached to a log group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group Name or ARNstringRequired/flomation/app

Returns: tool_result, log_group_identifier

AWS CloudWatch Logs Delete Log Group

aws/cloudwatchlogs/delete_log_group · Action

Delete a CloudWatch Logs log group and all its log streams and events.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/my-app

Returns: tool_result

AWS CloudWatch Logs Delete Log Stream

aws/cloudwatchlogs/delete_log_stream · Action

Delete a CloudWatch Logs log stream and all of its log events.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Log Stream NamestringRequired2026/07/22/[$LATEST]abc123

Returns: tool_result, log_stream_name

AWS CloudWatch Logs Delete Metric Filter

aws/cloudwatchlogs/delete_metric_filter · Action

Delete a metric filter from a CloudWatch Logs log group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Filter NamestringRequiredErrorCount

Returns: tool_result, filter_name

AWS CloudWatch Delete Query Definition

aws/cloudwatchlogs/delete_query_definition · Action

Delete a saved Logs Insights query definition by ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Query Definition IDstringRequired

Returns: tool_result, success

AWS CloudWatch Logs Delete Subscription Filter

aws/cloudwatchlogs/delete_subscription_filter · Action

Delete a subscription filter from a CloudWatch Logs log group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Filter NamestringRequiredship-logs

Returns: tool_result, filter_name

05Describe

AWS CloudWatch Describe Export Tasks

aws/cloudwatchlogs/describe_export_tasks · Action

List log export tasks, optionally filtered by task ID or status.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Task ID (optional)string
Status Code (optional)stringchoices: Cancelled, Completed, Failed, Pending, Pending Cancel, Running

Returns: tool_result, export_tasks, count

AWS CloudWatch Logs Describe Log Groups

aws/cloudwatchlogs/describe_log_groups · Action

List CloudWatch Logs log groups, optionally filtered by a name prefix.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group Name Prefix (optional)string/flomation/

Returns: tool_result, log_groups, count

AWS CloudWatch Logs Describe Log Streams

aws/cloudwatchlogs/describe_log_streams · Action

List the log streams within a CloudWatch Logs log group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/my-app
Log Stream Name Prefix (optional)string2026/07
Order By (optional)stringchoices: Log Stream Name, Last Event Time

Returns: tool_result, log_streams, count

AWS CloudWatch Logs Describe Metric Filters

aws/cloudwatchlogs/describe_metric_filters · Action

List CloudWatch Logs metric filters, optionally scoped to a log group or name prefix.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group Name (optional)string/flomation/app
Filter Name Prefix (optional)stringError

Returns: tool_result, metric_filters, count

AWS CloudWatch Describe Query Definitions

aws/cloudwatchlogs/describe_query_definitions · Action

List saved Logs Insights query definitions, optionally filtered by name prefix.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Name Prefix (optional)string

Returns: tool_result, query_definitions, count

AWS CloudWatch Logs Describe Subscription Filters

aws/cloudwatchlogs/describe_subscription_filters · Action

List the subscription filters attached to a CloudWatch Logs log group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Filter Name Prefix (optional)stringship-logs

Returns: tool_result, subscription_filters, count

06Filter

AWS CloudWatch Filter Log Events

aws/cloudwatchlogs/filter_log_events · Action

Search CloudWatch Logs across streams by filter pattern and time range.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Filter Pattern (optional)stringERROR
Start Time (RFC3339, optional)string2026-07-22T00:00:00Z
End Time (RFC3339, optional)string2026-07-22T23:59:59Z
Per-page Limit (optional)integer100

Returns: tool_result, events, count

07Get

AWS CloudWatch Get Data Protection Policy

aws/cloudwatchlogs/get_data_protection_policy · Action

Retrieve the data protection policy attached to a log group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group Name or ARNstringRequired/flomation/app

Returns: tool_result, policy_document, last_updated

AWS CloudWatch Get Log Events

aws/cloudwatchlogs/get_log_events · Action

Read log events from a CloudWatch Logs stream, optionally by time range.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Log Stream NamestringRequiredmy-stream
Start Time (RFC3339, optional)string2026-07-22T00:00:00Z
End Time (RFC3339, optional)string2026-07-22T23:59:59Z
Limit (optional)integer100
Oldest First (optional)boolean

Returns: tool_result, events, count

AWS CloudWatch Get Query Results

aws/cloudwatchlogs/get_query_results · Action

Fetch the results and status of a CloudWatch Logs Insights query.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Query IDstringRequiredFrom Start Query

Returns: tool_result, status, results, statistics

08Put

AWS CloudWatch Put Data Protection Policy

aws/cloudwatchlogs/put_data_protection_policy · Action

Attach a data protection policy that masks sensitive data in a log group.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group Name or ARNstringRequired/flomation/app
Policy Document (JSON)stringRequired{"Name":"MaskPII","Version":"2021-06-01","Statement":[...]}

Returns: tool_result, log_group_identifier

AWS CloudWatch Put Log Events

aws/cloudwatchlogs/put_log_events · Action

Write one or more log events to a CloudWatch Logs stream.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Log Stream NamestringRequiredmy-stream
MessagesstringRequiredA plain message, or a JSON array of {"timestamp","message"}

Returns: tool_result, next_sequence_token

AWS CloudWatch Put Metric Filter

aws/cloudwatchlogs/put_metric_filter · Action

Create or update a metric filter that emits CloudWatch metrics from log events.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Filter NamestringRequiredErrorCount
Filter PatternstringRequiredERROR
Metric Transformations (JSON array)stringRequired[{"metricName":"ErrorCount","metricNamespace":"Flomation","metricValue":"1"}]

Returns: tool_result, filter_name

AWS CloudWatch Put Query Definition

aws/cloudwatchlogs/put_query_definition · Action

Create or update a saved CloudWatch Logs Insights query definition.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Query NamestringRequiredErrors by service
Query StringstringRequiredfields @timestamp, @message | filter @message like /ERROR/
Log Group Names (comma-separated, optional)string/flomation/app,/flomation/api

Returns: tool_result, query_definition_id

AWS CloudWatch Logs Put Retention Policy

aws/cloudwatchlogs/put_retention_policy · Action

Set how many days a CloudWatch Logs log group retains its events.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/my-app
Retention (days)integerRequired30

Returns: tool_result

AWS CloudWatch Put Subscription Filter

aws/cloudwatchlogs/put_subscription_filter · Action

Stream matching log events from a log group to a destination (Lambda, Kinesis, Firehose).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Filter NamestringRequiredForwardErrors
Filter PatternstringRequiredERROR (empty matches all)
Destination ARNstringRequiredarn:aws:lambda:eu-west-2:...:function:...
Role ARN (optional)stringarn:aws:iam::...:role/...

Returns: tool_result, filter_name

09Start

AWS CloudWatch Start Query

aws/cloudwatchlogs/start_query · Action

Start a CloudWatch Logs Insights query over a log group and time range.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Log Group NamestringRequired/flomation/app
Query StringstringRequiredfields @timestamp, @message | sort @timestamp desc | limit 20
Start Time (RFC3339)stringRequired2026-07-22T00:00:00Z
End Time (RFC3339)stringRequired2026-07-22T23:59:59Z
Limit (optional)integer1000

Returns: tool_result, query_id

10Stop

AWS CloudWatch Logs Stop Query

aws/cloudwatchlogs/stop_query · Action

Stop a running CloudWatch Logs Insights query by its query ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Query IDstringRequired12ab3456-12ab-123a-789e-1234567890ab

Returns: tool_result, success

11Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • Logs Insights queries run asynchronously: Start Query returns only a query ID, so a later Get Query Results step must poll until the reported status is Complete before the rows are available.
  • Filter Log Events returns at most 200 matched events per run regardless of the per-page Limit you set, so narrow the time range or tighten the filter pattern rather than expecting an entire log group in one call.
  • Retention (days) accepts only the fixed set of values CloudWatch Logs supports — such as 1, 3, 5, 7, 14, 30, 60, 90, 365 and so on up to 3653 — and any other number is rejected.
  • Put Log Events timestamps are epoch milliseconds; when you pass a JSON array of events, supply millisecond values, and any entry left without a timestamp is stamped with the current time.
  • AWS allows only one active log export task per account at a time, so start a new Create Export Task only after the previous export has finished.