aws_logs_tail
Retrieves the newest CloudWatch Logs events from a log group over a recent time window (default 10 minutes), with optional filtering and limits. Returns each event's timestamp, log stream, and message.
Instructions
Fetch the newest CloudWatch Logs events for one log group over the last since (default 10m), via FilterLogEvents ('aws logs filter-log-events'). Returns events oldest first as {timestamp (ISO 8601 UTC), logStreamName, message (verbatim)}; any of the three is null on an event that arrived without it, which is kept rather than dropped. At most maxEvents come back (default 500, max 10000); when the window held more, the OLDEST are dropped and truncated is true. On AWS CLI 2.35.8+ the read goes newest-first and stops once it has enough, so a busy group costs a page or two -- and a truncated result reports totalEvents: null because the rest was never read. Older CLIs read the whole window (exact totalEvents); narrow since or add filterPattern if a wide window times out. logGroupName takes a bare name or a log-group ARN in the call's region; an ARN is sent as logGroupIdentifier, so a source-account ARN works from a cross-account monitoring account (AWS CLI 2.9.15+). Does not stream: call again for newer events. eventId and ingestionTime are omitted -- use aws_call for them.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| since | No | Window to tail: '<number><s|m|h|d|w>'. Default '10m'. Example: '30m', '1h', '3d'. Must be greater than zero and at most 30 days. | |
| region | No | Override session region for this call. | |
| profile | No | Override session profile for this call. | |
| maxEvents | No | Maximum events to return (1-10000). Default 500. Events come back oldest-first; when the window held more than this, the OLDEST are dropped, the newest are kept and truncated=true. On AWS CLI 2.35.8+ the read itself stops after this many events, so totalEvents is null when truncated is true; an older CLI scans the whole window and reports the exact totalEvents. Narrow 'since' or add a 'filterPattern' to make the call itself cheaper. | |
| timeoutMs | No | Timeout in milliseconds per aws CLI call (at most two per tool call). Default 60000 (60s). Raise for large windows. | |
| logGroupName | Yes | Log group name, e.g. '/aws/lambda/my-fn' or '/aws/ecs/my-service' (no leading 'logs/'). A full log-group ARN ('arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/my-fn', with or without a trailing ':*') is also accepted: it is sent as FilterLogEvents' logGroupIdentifier with the ':*' removed, so it reads the group in the ARN's own account. The ARN's region must match this call's region, and ARN input needs AWS CLI 2.9.15+. | |
| filterPattern | No | CloudWatch Logs filter pattern. E.g. 'ERROR', '"stack trace"', '[timestamp, request_id, level = ERROR, ...]'. | |
| logStreamNames | No | Restrict to specific stream names. Overrides the default (all streams in the group). | |
| logStreamNamePrefix | No | Restrict to streams with this prefix. Mutually exclusive with logStreamNames. |