AWS Certified Developer – Associate (DVA-C02)Troubleshooting and MonitoringMedium

A developer has configured AWS CloudWatch Logs to export logs from a Lambda function to an Amazon S3 bucket. They notice that while the Lambda function is actively generating logs, new log files are not appearing in the S3 bucket as expected. They've verified the CloudWatch Logs subscription filter is active and correctly points to the S3 destination. What is the MOST likely cause of this issue?

  1. AThe CloudWatch Logs subscription filter has an incorrect filter pattern, preventing logs from matching.
  2. BThe S3 bucket policy does not grant the CloudWatch Logs service principal `s3:PutObject` permissions.
  3. CThe Lambda function's execution role does not have `logs:CreateLogStream` permissions.
  4. DThe S3 bucket has versioning enabled, causing new objects to be stored as new versions rather than new files.
Show answer & explanation

Correct answer: B. The S3 bucket policy does not grant the CloudWatch Logs service principal `s3:PutObject` permissions.

For CloudWatch Logs to export logs to an S3 bucket, the S3 bucket policy must explicitly allow the CloudWatch Logs service principal (`logs.REGION.amazonaws.com`) to perform `s3:PutObject` actions on the bucket. Without this permission, CloudWatch Logs cannot write the exported log data to S3.

Why the other options are wrong

  • A. An incorrect filter pattern would prevent *specific* logs from being sent, but the problem states 'new log files are not appearing', suggesting a broader issue with the export mechanism itself, not just content filtering.
  • C. Missing `logs:CreateLogStream` would prevent the Lambda function from writing logs to CloudWatch Logs in the first place, but the question states logs are generated.
  • D. S3 versioning would store new objects as new versions, but they would still *appear* in the bucket. The issue is that files are 'not appearing' at all.

CloudWatch Logs to S3 Permissions

To export CloudWatch Logs to S3, the S3 bucket policy must grant the CloudWatch Logs service principal explicit `s3:PutObject` permission.

  • Service principal is `logs.REGION.amazonaws.com`.
  • Must be on the *destination* S3 bucket.
  • Separate from IAM roles for Lambda/EC2 logging *to* CloudWatch.

Memory trick: CloudWatch Logs needs the S3 bucket's 'permission stamp' to drop off logs.

More Troubleshooting and Monitoring questions