# Is there any way to access all cloudwatch log groups without providing the exact name?

**URL:** <https://discuss.elastic.co/t/is-there-any-way-to-access-all-cloudwatch-log-groups-without-providing-the-exact-name/186349>\
**Category:** Logstash\
**Created:** [June 18, 2019, 9:37pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-access-all-cloudwatch-log-groups-without-providing-the-exact-name/186349 "2019-06-18T21:37:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [June 18, 2019, 9:37pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-access-all-cloudwatch-log-groups-without-providing-the-exact-name/186349/1 "2019-06-18T21:37:03Z")

</div>

Hi everyone,

question about Logstash input plugin for Cloudwatch logs. I want to get all the logs in the log groups that start with /aws/lambda/, is that possible?

I tried the below configuration with log\_group =\> ["/aws/lambda/\*"], but it didn't work. However, using a specific log\_group name works, but that is not what I intend to do.

**Configuration:**

```
input{
 cloudwatch_logs {
   access_key_id => "***"
   secret_access_key => "***"
   log_group => ["/aws/lambda/*"]
   region => "us-west-2"
 }
}

filter { ... }

output { ... }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 18, 2019, 10:32pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-access-all-cloudwatch-log-groups-without-providing-the-exact-name/186349/2 "2019-06-18T22:32:40Z")

</div>

```
log_group_prefix => true

```

perhaps? I have not tested it, but from the code it appears to be what you want.

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [June 18, 2019, 10:52pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-access-all-cloudwatch-log-groups-without-providing-the-exact-name/186349/3 "2019-06-18T22:52:38Z")

</div>

> [@Badger](#):
>
> ```auto
> log_group_prefix => true
> 
> ```

Thanks for your suggestion, do I have to still specify the name of the log groups? or can I just use ["/aws/lambda/\*"] with the \* at the end of /aws/lambda/?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 18, 2019, 11:11pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-access-all-cloudwatch-log-groups-without-providing-the-exact-name/186349/4 "2019-06-18T23:11:41Z")

</div>

> [@EZprogramming](#):
>
> Thanks for your suggestion, do I have to still specify the name of the log groups? or can I just use ["/aws/lambda/\*"] with the \* at the end of /aws/lambda/?

You can walk through the [code](https://github.com/lukewaite/logstash-input-cloudwatch-logs/blob/bde0fd896418c5861d56639c2d5ae47abc0cb725/lib/logstash/inputs/cloudwatch_logs.rb#L141) and [API](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_DescribeLogGroups.html), or you can experiment. My best guess is

```
log_group => "/aws/lambda/"

```

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [June 19, 2019, 12:21am UTC](https://discuss.elastic.co/t/is-there-any-way-to-access-all-cloudwatch-log-groups-without-providing-the-exact-name/186349/5 "2019-06-19T00:21:18Z")

</div>

@Badger, yes the log group prefix worked. Thank you! 😀

**Solution:**

```
input{
  cloudwatch_logs {
    access_key_id => "***"
    secret_access_key => "***"
    log_group_prefix => true
    log_group => ["/aws/lambda/"]
    region => "us-west-2"
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2019, 12:21am UTC](https://discuss.elastic.co/t/is-there-any-way-to-access-all-cloudwatch-log-groups-without-providing-the-exact-name/186349/6 "2019-07-17T00:21:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
