shiichan

Syslog Straight Into CloudWatch Logs, No Agents Required!

Hey there, it's Shiichan! Today I found a nice little update that makes log collection a bit easier.

AWS What's New aws.amazon.com

What was announced?

Over on the AWS "What's New" feed, Amazon CloudWatch Logs announced support for managed syslog ingestion. You can now send syslog messages from your network gear and servers straight into CloudWatch Logs, without deploying or running any collection agents.

The story so far

Until now, getting syslog into CloudWatch meant rolling out collection agents and keeping them maintained. For devices where an agent is awkward to install, like routers, switches, and firewalls, pulling their logs into one place was a small but real chore.

What changes

Now you can push syslog directly into CloudWatch Logs, so you can consolidate infrastructure log visibility across distributed environments in one spot. Incoming messages are parsed automatically into structured fields like facility, severity, hostname, and application name. That means you can query by severity or hostname in Logs Analytics right away, which speeds up security investigations and troubleshooting.

Dive Deep

The service accepts messages over TCP, TCP+TLS, and UDP. Supported syslog formats include RFC 5424, RFC 3164, and the Cisco FTD/ASA formats.

It is available in all commercial AWS Regions except Middle East (UAE), Middle East (Bahrain), and Israel (Tel Aviv). For setup details, check the CloudWatch Logs documentation.

Wrap-up

  • Amazon CloudWatch Logs now supports managed syslog ingestion (from the AWS What's New feed)
  • No agents needed to ingest syslog from network devices and servers
  • Works over TCP / TCP+TLS / UDP, with RFC 5424, RFC 3164, and Cisco FTD/ASA formats
  • Automatic parsing into facility, severity, hostname, and application name, searchable in Logs Analytics
  • Available in all commercial Regions except a few

If you have been wrestling with collecting logs from routers and switches, this one's for you!