Skip to main content

CloudWatch Logs Start Query

Schedules a query of a log group using CloudWatch Logs Insights. You specify the log group and time range to query and the query string to use.

For more information, see CloudWatch Logs Insights Query Syntax.

Queries time out after 15 minutes of execution. If your queries are timing out, reduce the time range being searched or partition your query into a number of queries.

External Documentation

To learn more, visit the AWS documentation.

Basic Parameters

ParameterDescription
AWS Region(s)Enter the desired AWS Region(s).

To execute the action in multiple regions, provide a comma-separated list.
For example: us-east-1,eu-west-2.

If you wish to run the action in all available regions, use the asterisk symbol (*) instead.
End TimeThe end of the time range to query. The range is inclusive, so the specified end time is included in the query.
Specified as epoch time, the number of seconds since January 1, 1970, 00:00:00 UTC.
Log Group NameThe log group on which to perform the query.
A StartQuery operation must include a logGroupNames or a logGroupName parameter, but not both.
Log Group NamesThe list of log groups to be queried. You can include up to 20 log groups.
A StartQuery operation must include a logGroupNames or a logGroupName parameter, but not both.
Query StringThe query string to use. For more information, see CloudWatch Logs Insights Query Syntax (https:docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CWL_QuerySyntax.html).
Start TimeThe beginning of the time range to query. The range is inclusive, so the specified start time is included in the query.
Specified as epoch time, the number of seconds since January 1, 1970, 00:00:00 UTC.

Advanced Parameters

ParameterDescription
Disable XML To JSON Auto ConvertWhen checked, XML responses are not automatically converted into JSON format.
LimitThe maximum number of log events to return in the query.
If the query string uses the fields command, only the specified fields and their values are returned.
The default is 1000.

Example Output

{
"queryId": "string"
}

Automation Library Example

Cloudwatch Logs Start Query with Aws and Send Results Via Email

Automation LibraryPreview this Automation on desktop