---
title: "AWS Cloudwatch Logs Input"
description: "read events from AWS CloudWatch Logs"
source: "https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/analyzer/cloudwatchLogs/module.yaml"
icon: "fontawesome/brands/aws"

---
Configures an AWS CloudWatch Logs input from which to read events to transform into typed [TenXObjects](https://doc.log10x.com/api/js/#TenXObject "Provide structured, reflective access to log/trace events read from input(s).").

Instances of this [module](https://doc.log10x.com/engine/module/) define a connection to an AWS CloudWatch Logs service
from which to retrieve log messages, as well as the querying logic used
such as chronological direction, start values, time ranges, and page size
of each API request sent.

Cloudwatch Logs inputs commonly run within scheduled jobs (e.g., k8s CronJob)
to retrieve a recent sample amount of events (e.g., 200MB in the last 10min) to [transform](https://doc.log10x.com/run/transform/ "Transform log and trace events into well-defined TenXObjects") into TenXObjects as part of the [Dev app](https://doc.log10x.com/apps/dev/) app.

## :material-wrench-outline: Config Files

To configure the AWS Cloudwatch Logs input module, [:material-cog: Edit](https://doc.log10x.com/config/app/#module-config "Learn how to edit app and module configurations") these files.  

Below is the default configuration from: [cloudwatchLogs/config.yaml](https://github.dev/log-10x/config/blob/main/pipelines/run/input/analyzer/cloudwatchLogs/config.yaml "cloudwatchLogs/config.yaml"){target="\_blank"} (<span class="tenx-tooltip" data-tooltip="The config file below contains required fields to activate this module, marked with &#10071;">** Required Fields*</span>).  
  
<div class="edit-options">
    <a class="md-button tenx-edit-online-button" data-tooltip="Edit online on github.dev" href="https://github.dev/log-10x/config/blob/main/pipelines/run/input/analyzer/cloudwatchLogs/config.yaml" target="_blank" rel="noopener noreferrer">
        <span class="twemoji" style="margin-right: 0.3rem;">
            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                <path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path>
            </svg>
        </span> Edit Online
    </a>
    <button class="md-button tenx-config.yaml0-edit-button" data-tooltip="Edit configuration file" data-dialog-id="config-yaml0-dialog">
        <span style="margin-right: 0.3rem;">
            <span class="twemoji">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                    <path d="M20.71,7.04C21.1,6.65 21.1,6 20.71,5.63L18.37,3.29C18,2.9 17.35,2.9 16.96,3.29L15.12,5.12L18.87,8.87M3,17.25V21H6.75L17.81,9.93L14.06,6.18L3,17.25Z"></path>
                </svg>
            </span>
        </span>Edit Locally
    </button>
</div>

<dialog id="config-yaml0-dialog" class="md-dialog md-dialog--editor">
    <div class="editor-dialog-wrapper">
        <div class="editor-dialog-header">
            <span class="editor-dialog-title">Edit config.yaml Locally</span>
            <div class="editor-header-actions">
                <button class="editor-toolbar-btn yaml-editor-locations" data-tooltip="Save">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-reset" data-tooltip="Reset to default">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M12.5 8c-2.65 0-5.05 1-6.9 2.6L2 7v9h9l-3.62-3.62c1.39-1.16 3.16-1.88 5.12-1.88 3.54 0 6.55 2.31 7.6 5.5l2.37-.78C21.08 11.03 17.15 8 12.5 8z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-copy" data-tooltip="Copy to clipboard">
                    <svg class="icon-copy" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path></svg>
                    <svg class="icon-check" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn yaml-editor-fullscreen" data-tooltip="Fullscreen">
                    <svg class="icon-maximize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5,5H10V7H7V10H5V5M14,5H19V10H17V7H14V5M17,14H19V19H14V17H17V14M10,17V19H5V14H7V17H10Z"></path></svg>
                    <svg class="icon-minimize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M5,16H8V19H10V14H5V16M14,14V19H16V16H19V14H14M16,5V8H19V10H14V5H16M10,5V10H5V8H8V5H10Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn editor-dialog-close" onclick="closeDialog('config-yaml0-dialog')" data-tooltip="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path></svg>
                </button>
            </div>
        </div>
        <div class="editor-dialog-content">
            <div class="yaml-editor-container"></div>
        </div>
        <div class="yaml-editor-statusbar">
            <span class="yaml-editor-status"></span>
        </div>
    </div>
    <!-- Locations Popup -->
    <div class="locations-popup" style="display: none;">
        <div class="locations-popup-content">
            <div class="locations-popup-header">
                <span class="locations-header-label">Download and save to:</span>
                <button class="locations-popup-close" aria-label="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16">
                        <path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path>
                    </svg>
                </button>
            </div>
            <ul class="locations-list">
                <li>
                    <span class="location-label">Linux / Docker / macOS
                        <span class="help-icon" data-tooltip="Default system location. The engine automatically reads configs from here at startup. Best for production deployments.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="default-path location-path" data-tooltip=""
                            data-copy-osx="/etc/log10x/config/run/input/analyzer/cloudwatchLogs/config.yaml"
                            data-copy-nix="/etc/log10x/config/run/input/analyzer/cloudwatchLogs/config.yaml"
                            data-copy-win="C:\log10x\configs/run/input/analyzer/cloudwatchLogs/config.yaml"></code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Custom directory
                        <span class="help-icon" data-tooltip="Set TENX_CONFIG environment variable to point to a custom config directory. Useful when you want configs in a non-standard location.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="$TENX_CONFIG/run/input/analyzer/cloudwatchLogs/config.yaml">$TENX_CONFIG/run/input/analyzer/cloudwatchLogs/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Within cloned repo
                        <span class="help-icon" data-tooltip="First run: git clone github.com/log-10x/config. Then save the file to this path within the cloned folder. Use for version control.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="./pipelines/run/input/analyzer/cloudwatchLogs/config.yaml">./pipelines/run/input/analyzer/cloudwatchLogs/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
            </ul>
            <div class="locations-popup-footer">
                <button class="locations-download-btn" title="Download config file">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                        <path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path>
                    </svg>
                    <span>Download</span>
                </button>
            </div>
        </div>
    </div>
</dialog>

<template class="tenx-config-schema" data-encoding="base64">ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJpbmNsdWRlIiA6IHsKICAgICAgInR5cGUiIDogInN0cmluZyIKICAgIH0sCiAgICAidGVueCIgOiB7CiAgICAgICJ0eXBlIiA6ICJzdHJpbmciCiAgICB9LAogICAgImNsb3Vkd2F0Y2hMb2dzIiA6IHsKICAgICAgInR5cGUiIDogImFycmF5IiwKICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAidHlwZSIgOiAib2JqZWN0IiwKICAgICAgICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UsCiAgICAgICAgInByb3BlcnRpZXMiIDogewogICAgICAgICAgIm5hbWUiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJMb2dpY2FsIG5hbWUgZm9yIHRoaXMgQVdTIENsb3VkV2F0Y2ggTG9ncyBpbnB1dFxuXG5TZXRzIGEgbG9naWNhbCBuYW1lIChlLmcuLCAnbXlDbG91ZFdhdGNoTG9ncycpIGZvciB0aGlzIGlucHV0LiBUaGUgW2lucHV0TmFtZV0oaHR0cHM6Ly9kb2MubG9nMTB4LmNvbS9hcGkvanMvI1RlblhCYXNlT2JqZWN0K2lucHV0TmFtZSkgZmllbGQgIHJldHVybnMgdGhpcyB2YWx1ZSBhdCBydW4gdGltZSB0byBhbGxvdyBmb3IgaWRlbnRpZnlpbmcgYW5kIG9wZXJhdGluZyBvbiBpbnN0YW5jZXMgb3JpZ2luYXRpbmcgZnJvbSB0aGlzIGlucHV0LiIKICAgICAgICAgIH0sCiAgICAgICAgICAiZW5hYmxlZCIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAiYm9vbGVhbiIsCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJTZXRzIHdoZXRoZXIgdGhpcyBpbnB1dCBpcyBlbmFibGVkXG5cblNldHMgd2hldGhlciB0byBvcGVuIHRoZSBpbnB1dCBzdHJlYW0uIFRvIGVuYWJsZSB0aGlzIGlucHV0IG9ubHkgd2hlbiBhICdjbG91ZHdhdGNoTG9nc05hbWUnIHN0YXJ0dXAgYXJndW1lbnQgdmFsdWUgaXMgdHJ1dGh5LCB1c2U6IGBgYCB5YW1sIGNsb3Vkd2F0Y2hMb2dzRW5hYmxlZDogJD1UZW5YRW52LmdldChcImNsb3Vkd2F0Y2hMb2dzTmFtZVwiKSBgYGAgVG8gbGVhcm4gbW9yZSBzZWUgW1RlblhFbnYuZ2V0XShodHRwczovL2RvYy5sb2cxMHguY29tL2FwaS9qcy8jVGVuWEVudi5nZXQpLiAoQWNjZXB0cyBib29sZWFuIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSIKICAgICAgICAgIH0sCiAgICAgICAgICAicHJpbnRQcm9ncmVzcyIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAiYm9vbGVhbiIsCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJTZXRzIHdoZXRoZXIgdGhpcyBpbnB1dCBwcmludHMgdGhyb3VnaHB1dCBzdGF0cyB0byB0aGUgY29uc29sZVxuXG5TZXRzIHdoZXRoZXIgdGhpcyBpbnB1dCBwcmludHMgdGhyb3VnaHB1dCBzdGF0cyB0byB0aGUgY29uc29sZSBmb3IgdGVzdGluZyBhbiBpbnRlZ3JhdGlvbiB0byBhIHJlbW90ZSBlbmRwb2ludC4gKEFjY2VwdHMgYm9vbGVhbiBvciBzdHJpbmcgd2l0aCAkPSBwcmVmaXggZm9yIHJ1bnRpbWUgZXZhbHVhdGlvbikgKERlZmF1bHQ6IGZhbHNlKSIsCiAgICAgICAgICAgICJkZWZhdWx0IiA6IGZhbHNlCiAgICAgICAgICB9LAogICAgICAgICAgImF3c1JlZ2lvbiIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIkFXUyByZWdpb25cblxuU2V0cyB0aGUgQVdTIHJlZ2lvbiAoZS5nLiwgJ3VzLWVhc3QtMScpIGhvc3RpbmcgdGhlIHRhcmdldCBDbG91ZFdhdGNoIGxvZ3Mgc3RyZWFtLiAgIFRvIGxlYXJuIG1vcmUgc2VlIFtBV1MgUmVnaW9uc10oaHR0cHM6Ly9kb2NzLmF3cy5hbWF6b24uY29tL0FXU0VDMi9sYXRlc3QvVXNlckd1aWRlL3VzaW5nLXJlZ2lvbnMtYXZhaWxhYmlsaXR5LXpvbmVzLmh0bWwpIgogICAgICAgICAgfSwKICAgICAgICAgICJhd3NBY2Nlc3NLZXlJRCIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIkFXUyBhdXRoZW50aWNhdGlvbiBhY2Nlc3Mga2V5IElEXG5cblNldHMgdGhlIEFXUyBhY2Nlc3Mga2V5IChlLmcuLCAnQUtJQUlPU0ZPRE5ON0VYQU1QTEUnKSB1c2VkIGFzIHBhcnQgb2YgdGhlIHJlcXVlc3Qgc2lnbmluZyBwcm9jZXNzLiAgKipJZiBub3Qgc3BlY2lmaWVkKiosIHRoZSBzeXN0ZW0gYXV0b21hdGljYWxseSBmYWxscyBiYWNrIHRvIHRoZSBbQVdTIGRlZmF1bHQgY3JlZGVudGlhbCBwcm92aWRlciBjaGFpbl0oaHR0cHM6Ly9kb2NzLmF3cy5hbWF6b24uY29tL3Nkay1mb3ItamF2YS9sYXRlc3QvZGV2ZWxvcGVyLWd1aWRlL2NyZWRlbnRpYWxzLWNoYWluLmh0bWwpLCB3aGljaCBjaGVja3MgKGluIG9yZGVyKTogIDEuIEVudmlyb25tZW50IHZhcmlhYmxlcyAoYEFXU19BQ0NFU1NfS0VZX0lEYCwgYEFXU19TRUNSRVRfQUNDRVNTX0tFWWApIDIuIEphdmEgc3lzdGVtIHByb3BlcnRpZXMgMy4gV2ViIGlkZW50aXR5IHRva2VuIChmb3IgRUtTKSA0LiBTaGFyZWQgY3JlZGVudGlhbHMgZmlsZSAoYH4vLmF3cy9jcmVkZW50aWFsc2ApIDUuIEVDUyBjb250YWluZXIgY3JlZGVudGlhbHMgNi4gRUMyIGluc3RhbmNlIHByb2ZpbGUgY3JlZGVudGlhbHMgIFRvIGxlYXJuIG1vcmUgc2VlIFtBV1MgYWNjZXNzIGtleXNdKGh0dHBzOi8vZG9jcy5hd3MuYW1hem9uLmNvbS9JQU0vbGF0ZXN0L1VzZXJHdWlkZS9pZF9jcmVkZW50aWFsc19hY2Nlc3Mta2V5cy5odG1sKSIKICAgICAgICAgIH0sCiAgICAgICAgICAiYXdzU2VjcmV0S2V5IiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiQVdTIGF1dGhlbnRpY2F0aW9uIHNlY3JldCBrZXlcblxuU2V0cyB0aGUgQVdTIGFjY2VzcyBzZWNyZXQga2V5IChlLmcuICd3SmFsclhVdG5GRU1JL0s3TURFTkcvYlB4UmZpQ1lFWEFNUExFS0VZJykgdXNlZCBhcyBwYXJ0IG9mIHRoZSByZXF1ZXN0IHNpZ25pbmcgcHJvY2Vzcy4gICoqSWYgbm90IHNwZWNpZmllZCoqLCB0aGUgc3lzdGVtIGF1dG9tYXRpY2FsbHkgZmFsbHMgYmFjayB0byB0aGUgW0FXUyBkZWZhdWx0IGNyZWRlbnRpYWwgcHJvdmlkZXIgY2hhaW5dKGh0dHBzOi8vZG9jcy5hd3MuYW1hem9uLmNvbS9zZGstZm9yLWphdmEvbGF0ZXN0L2RldmVsb3Blci1ndWlkZS9jcmVkZW50aWFscy1jaGFpbi5odG1sKS4gVGhpcyBhbGxvd3MgdXNpbmcgY3JlZGVudGlhbHMgZnJvbSBgfi8uYXdzL2NyZWRlbnRpYWxzYCwgSUFNIHJvbGVzLCBvciBlbnZpcm9ubWVudCB2YXJpYWJsZXMgd2l0aG91dCBleHBsaWNpdCBjb25maWd1cmF0aW9uLiAgVG8gbGVhcm4gbW9yZSBzZWUgW0FXUyBzZWN1cml0eSBjcmVkZW50aWFsc10oaHR0cHM6Ly9kb2NzLmF3cy5hbWF6b24uY29tL2dlbmVyYWwvbGF0ZXN0L2dyL2F3cy1zZWMtY3JlZC10eXBlcy5odG1sKSIKICAgICAgICAgIH0sCiAgICAgICAgICAiZ3JvdXBOYW1lIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiQVdTIENsb3VkV2F0Y2ggTG9ncyBHcm91cCBuYW1lXG5cblVzZWQgd2l0aGluIHRoZSBib2R5IG9mIHRoZSAnR2V0TG9nRXZlbnRzJyBBV1MgcmVxdWVzdCB0byBzcGVjaWZ5IHRoZSBsb2cgZ3JvdXAgbmFtZSAoZS5nLiwgJ215LWxvZy1ncm91cCcpLiAgIFRvIGxlYXJuIG1vcmUgc2VlIFtsb2dHcm91cE5hbWVdKGh0dHBzOi8vZG9jcy5hd3MuYW1hem9uLmNvbS9BbWF6b25DbG91ZFdhdGNoTG9ncy9sYXRlc3QvQVBJUmVmZXJlbmNlL0FQSV9HZXRMb2dFdmVudHMuaHRtbCNDV0wtR2V0TG9nRXZlbnRzLXJlcXVlc3QtbG9nR3JvdXBOYW1lKSIKICAgICAgICAgIH0sCiAgICAgICAgICAic3RyZWFtTmFtZSIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIkFXUyBDbG91ZFdhdGNoIExvZ3MgU3RyZWFtIG5hbWVcblxuVXNlZCB3aXRoaW4gdGhlIGJvZHkgb2YgdGhlIEFXUyAnQUdldExvZ0V2ZW50cycgcmVxdWVzdCB0byBzcGVjaWZ5IHRoZSBsb2cgc3RyZWFtIG5hbWUgKGUuZy4sICdteS1sb2ctc3RyZWFtJykuICBUbyBsZWFybiBtb3JlIHNlZSBbbG9nU3RyZWFtTmFtZV0oaHR0cHM6Ly9kb2NzLmF3cy5hbWF6b24uY29tL0FtYXpvbkNsb3VkV2F0Y2hMb2dzL2xhdGVzdC9BUElSZWZlcmVuY2UvQVBJX0dldExvZ0V2ZW50cy5odG1sI0NXTC1HZXRMb2dFdmVudHMtcmVxdWVzdC1sb2dTdHJlYW1OYW1lKSIKICAgICAgICAgIH0sCiAgICAgICAgICAibGltaXQiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgIm51bWJlciIsCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJOdW1iZXIgb2YgZXZlbnRzIHRvIHJlYWQgcGVyIGJhdGNoIGZyb20gdGhlIEFXUyBDbG91ZFdhdGNoIExvZ3Mgc2VydmljZVxuXG5TZXRzIHRoZSBudW1iZXIgb2YgZG9jdW1lbnRzIHRvIHJldHJpZXZlIHdpdGggZWFjaCBwYWdlIG9mIHJlc3VsdHMuIFRvIGxlYXJuIG1vcmUgc2VlOiBbcmVxdWVzdCBsaW1pdF0oaHR0cHM6Ly9kb2NzLmF3cy5hbWF6b24uY29tL0FtYXpvbkNsb3VkV2F0Y2hMb2dzL2xhdGVzdC9BUElSZWZlcmVuY2UvQVBJX0dldExvZ0V2ZW50cy5odG1sI0NXTC1HZXRMb2dFdmVudHMtcmVxdWVzdC1saW1pdCkgKEFjY2VwdHMgbnVtYmVyIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSAoRGVmYXVsdDogNTAwKSIsCiAgICAgICAgICAgICJkZWZhdWx0IiA6IDUwMAogICAgICAgICAgfSwKICAgICAgICAgICJuZXh0VG9rZW4iIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJUaGUgdG9rZW4gZm9yIHRoZSBuZXh0IHNldCBvZiBpdGVtcyB0byByZXR1cm4gKHJlY2VpdmVkIHRoaXMgdG9rZW4gZnJvbSBhIHByZXZpb3VzIGNhbGwpXG5cblNldHMgdGhlIHRva2VuIGZyb20gd2hpY2ggdGhlIHJlcXVlc3RlZCByZXN1bHQgcGFnZSBpcyB0byBzdGFydC4gVGhpcyB2YWx1ZSBpcyByZXR1cm5lZCBmcm9tIGEgcHJldmlvdXMgY2FsbCB0byB0aGUgQVdTICdHZXRMb2dFdmVudHMnIGNvbW1hbmQuIFRvIGxlYXJuIG1vcmUgc2VlOiBbbmV4dFRva2VuXShodHRwczovL2RvY3MuYXdzLmFtYXpvbi5jb20vQW1hem9uQ2xvdWRXYXRjaExvZ3MvbGF0ZXN0L0FQSVJlZmVyZW5jZS9BUElfR2V0TG9nRXZlbnRzLmh0bWwjQ1dMLUdldExvZ0V2ZW50cy1yZXF1ZXN0LW5leHRUb2tlbikiCiAgICAgICAgICB9LAogICAgICAgICAgInN0YXJ0RnJvbUhlYWQiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgImJvb2xlYW4iLAogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiSWYgdHJ1ZSwgcmV0dXJuIHRoZSBlYXJsaWVzdCBsb2cgZXZlbnRzIGZpcnN0LiBJZiBmYWxzZSwgcmV0dXJuIHRoZSBtb3N0IHJlY2VudCBsb2cgZXZlbnRzIGZpcnN0LlxuXG5Db250cm9scyB0aGUgZGlyZWN0aW9uIG9mIHRoZSBzZWFyY2ggKG9sZCA8LT4gbmV3IGV2ZW50cykuIEJ5IGRlZmF1bHQsIHRoZSBzZWFyY2ggc3RhcnRzIGZyb20gdGhlIG1vc3QgcmVjZW50IGV2ZW50cy4gVG8gbGVhcm4gbW9yZSBzZWU6IFtzdGFydEZyb21IZWFkXShodHRwczovL2RvY3MuYXdzLmFtYXpvbi5jb20vQW1hem9uQ2xvdWRXYXRjaExvZ3MvbGF0ZXN0L0FQSVJlZmVyZW5jZS9BUElfR2V0TG9nRXZlbnRzLmh0bWwjQ1dMLUdldExvZ0V2ZW50cy1yZXF1ZXN0LXN0YXJ0RnJvbUhlYWQpIChBY2NlcHRzIGJvb2xlYW4gb3Igc3RyaW5nIHdpdGggJD0gcHJlZml4IGZvciBydW50aW1lIGV2YWx1YXRpb24pIChEZWZhdWx0OiBmYWxzZSkiLAogICAgICAgICAgICAiZGVmYXVsdCIgOiBmYWxzZQogICAgICAgICAgfSwKICAgICAgICAgICJzdGFydFRpbWUiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgIm51bWJlciIsCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJUaGUgc3RhcnQgb2YgdGhlIHRpbWUgcmFuZ2UsIGV4cHJlc3NlZCBhcyB0aGUgbnVtYmVyIG9mIG1pbGxpc2Vjb25kcyBhZnRlciBKYW4gMSwgMTk3MCAwMDowMDowMCBVVEMuXG5cblNldHMgdGhlIHN0YXJ0IG9mIHRoZSB0aW1lIHJhbmdlLCBleHByZXNzZWQgYXMgbWlsbGlzZWNvbmRzIGFmdGVyIEphbiAxLCAxOTcwIDAwOjAwOjAwIFVUQy4gRXZlbnRzIHdpdGggYSB0aW1lc3RhbXAgZXF1YWwgdG8gdGhpcyB0aW1lIG9yIGxhdGVyIHRoYW4gdGhpcyB0aW1lIGFyZSBpbmNsdWRlZC4gRXZlbnRzIHdpdGggYSB0aW1lc3RhbXAgZWFybGllciB0aGFuIHRoaXMgdGltZSBhcmUgZXhjbHVkZWQ6IFRvIGxlYXJuIG1vcmUgc2VlOiBbc3RhcnRUaW1lXShodHRwczovL2RvY3MuYXdzLmFtYXpvbi5jb20vQW1hem9uQ2xvdWRXYXRjaExvZ3MvbGF0ZXN0L0FQSVJlZmVyZW5jZS9BUElfR2V0TG9nRXZlbnRzLmh0bWwjQ1dMLUdldExvZ0V2ZW50cy1yZXF1ZXN0LXN0YXJ0VGltZSkgKEFjY2VwdHMgbnVtYmVyIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSIKICAgICAgICAgIH0sCiAgICAgICAgICAiZW5kVGltZSIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAibnVtYmVyIiwKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlRoZSBlbmQgb2YgdGhlIHRpbWUgcmFuZ2UsIGV4cHJlc3NlZCBhcyB0aGUgbnVtYmVyIG9mIG1pbGxpc2Vjb25kcyBhZnRlciBKYW4gMSwgMTk3MCAwMDowMDowMCBVVENcblxuU2V0cyB0aGUgZW5kIG9mIHRoZSB0aW1lIHJhbmdlLCBleHByZXNzZWQgYXMgbWlsbGlzZWNvbmRzIGFmdGVyIEphbiAxLCAxOTcwIDAwOjAwOjAwIFVUQy4gRXZlbnRzIHdpdGggYSB0aW1lc3RhbXAgZXF1YWwgdG8gb3IgbGF0ZXIgdGhhbiB0aGlzIHRpbWUgYXJlIG5vdCBpbmNsdWRlZDogVG8gbGVhcm4gbW9yZSBzZWU6IFtlbmRUaW1lXShodHRwczovL2RvY3MuYXdzLmFtYXpvbi5jb20vQW1hem9uQ2xvdWRXYXRjaExvZ3MvbGF0ZXN0L0FQSVJlZmVyZW5jZS9BUElfR2V0TG9nRXZlbnRzLmh0bWwjQ1dMLUdldExvZ0V2ZW50cy1yZXF1ZXN0LWVuZFRpbWUpIChBY2NlcHRzIG51bWJlciBvciBzdHJpbmcgd2l0aCAkPSBwcmVmaXggZm9yIHJ1bnRpbWUgZXZhbHVhdGlvbikiCiAgICAgICAgICB9LAogICAgICAgICAgInJldHJ5VGltZW91dCIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAibnVtYmVyIiwKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIkEgdGltZW91dCBwZXJpb2QgKGluIG1pbGxpc2Vjb25kcykgdG8gd2FpdCBmb3IgcXVlcnlpbmcgb2YgbmV3IGRhdGFcblxuVXNlZCBieSBbY2xvdWR3YXRjaExvZ3MtaW5wdXQuanNdKGh0dHBzOi8vZ2l0aHViLmNvbS9sb2ctMTB4L21vZHVsZXMvYmxvYi9tYWluL3BpcGVsaW5lcy9ydW4vbW9kdWxlcy9pbnB1dC9hbmFseXplci9jbG91ZHdhdGNoTG9ncy9jbG91ZHdhdGNoTG9ncy1pbnB1dC5qcykgdG8gZGV0ZXJtaW5lIGhvdyBsb25nIHRvIHdhaXQgdG8gaW52b2tlIHRoZSAnR2V0TG9nRXZlbnRzJyBBUEkgYWdhaW4gdG8gcXVlcnkgZm9yIG5ldyBkYXRhLiAoQWNjZXB0cyBudW1iZXIgb3Igc3RyaW5nIHdpdGggJD0gcHJlZml4IGZvciBydW50aW1lIGV2YWx1YXRpb24pIChEZWZhdWx0OiAyMDAwMCkiLAogICAgICAgICAgICAiZGVmYXVsdCIgOiAyMDAwMAogICAgICAgICAgfSwKICAgICAgICAgICJ0b3RhbEJ5dGVzTGltaXQiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgIm51bWJlciIsCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJNYXhpbXVtIHRvdGFsIGJ5dGVzIHRvIHJlYWQgZnJvbSBpbnB1dCBiZWZvcmUgY2xvc2luZ1xuXG5TZXRzIHRoZSBtYXhpbXVtIG51bWJlciBvZiBieXRlcyBhIHRhcmdldCBwaXBlbGluZSBpbnB1dCB3aWxsIHJlYWQgaW50byB0aGUgcGlwZWxpbmUuIFRoaXMgdmFsdWUgbGltaXRzIHRoZSB2b2x1bWUgb2YgZXZlbnRzIHRvIHJlYWQgZnJvbSBhIGxvY2FsL3JlbW90ZSBzb3VyY2UgKGUuZy4sIGxvZyBhbmFseXplcikuICAgRm9yIGV4YW1wbGU6IGBgYCB5YW1sIHRvdGFsQnl0ZXNMaW1pdDogJD1wYXJzZUJ5dGVzKFwiMUdCXCIpIGBgYCAoQWNjZXB0cyBudW1iZXIgb3Igc3RyaW5nIHdpdGggJD0gcHJlZml4IGZvciBydW50aW1lIGV2YWx1YXRpb24pIgogICAgICAgICAgfSwKICAgICAgICAgICJ0b3RhbEV2ZW50c0xpbWl0IiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJudW1iZXIiLAogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiTWF4aW11bSB0b3RhbCBldmVudHMgdG8gcmVhZCBmcm9tIGlucHV0IGJlZm9yZSBjbG9zaW5nXG5cblNldHMgdGhlIG1heGltdW0gbnVtYmVyIG9mIGV2ZW50cyBhIHRhcmdldCBwaXBlbGluZSBpbnB1dCB3aWxsIHJlYWQgaW50byB0aGUgcGlwZWxpbmUuIFRoaXMgdmFsdWUgbGltaXRzIHRoZSB2b2x1bWUgb2YgZXZlbnRzIHRvIHJlYWQgZnJvbSBhIGxvY2FsL3JlbW90ZSBzb3VyY2UgKGUuZy4sIGxvZyBhbmFseXplcikuIChBY2NlcHRzIG51bWJlciBvciBzdHJpbmcgd2l0aCAkPSBwcmVmaXggZm9yIHJ1bnRpbWUgZXZhbHVhdGlvbikgKERlZmF1bHQ6IDEwMDAwKSIsCiAgICAgICAgICAgICJkZWZhdWx0IiA6IDEwMDAwCiAgICAgICAgICB9LAogICAgICAgICAgInRvdGFsRHVyYXRpb24iIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJNYXhpbXVtIGR1cmF0aW9uIHRvIGtlZXAgaW5wdXQgb3BlbiBiZWZvcmUgY2xvc2luZ1xuXG5TZXRzIHRoZSBtYXhpbXVtIGR1cmF0aW9uIGEgdGFyZ2V0IHBpcGVsaW5lIGlucHV0IHdpbGwgcmVtYWluIG9wZW4uIFdoZW4gcmVhY2hlZCwgdGhlIGlucHV0IHdpbGwgY2xvc2UgYW5kIG5vIG1vcmUgZGF0YSB3aWxsIGJlIHJlYWQuICBGb3IgZXhhbXBsZTogYGBgIHlhbWwgY2xvdWR3YXRjaExvZ3NUb3RhbER1cmF0aW9uOiAkPXBhcnNlRHVyYXRpb24oXCIxMG1pblwiKSBgYGAgKERlZmF1bHQ6IHBhcnNlRHVyYXRpb24oXCI1bWluXCIpKSIsCiAgICAgICAgICAgICJkZWZhdWx0IiA6ICJwYXJzZUR1cmF0aW9uKFwiNW1pblwiKSIKICAgICAgICAgIH0sCiAgICAgICAgICAicXVlcnlJbnRlcnZhbCIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAibnVtYmVyIiwKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlF1ZXJ5IGludGVydmFsIChpbiBtaWxsaXNlY29uZHMpIGZvciBjaGVja2luZyBuZXcgZGF0YSBmcm9tIHJlbW90ZSBzb3VyY2VcblxuU2V0cyB0aGUgaW50ZXJ2YWwgYmV0d2VlbiBxdWVyaWVzIHRvIHRoZSByZW1vdGUgQ2xvdWRXYXRjaCBMb2dzIEFQSS4gVGhpcyBjb250cm9scyBob3cgZnJlcXVlbnRseSB0aGUgaW5wdXQgcG9sbHMgZm9yIG5ldyBsb2cgZGF0YS4gIEZvciBleGFtcGxlOiBgYGAgeWFtbCBjbG91ZHdhdGNoTG9nc1F1ZXJ5SW50ZXJ2YWw6ICQ9cGFyc2VEdXJhdGlvbihcIjVzXCIpIGBgYCAoQWNjZXB0cyBudW1iZXIgb3Igc3RyaW5nIHdpdGggJD0gcHJlZml4IGZvciBydW50aW1lIGV2YWx1YXRpb24pIChEZWZhdWx0OiAyMDAwKSIsCiAgICAgICAgICAgICJkZWZhdWx0IiA6IDIwMDAKICAgICAgICAgIH0sCiAgICAgICAgICAibWVzc2FnZUZpZWxkIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiSlNPTiBmaWVsZCBuYW1lIHRvIGV4dHJhY3QgZnJvbSBDbG91ZFdhdGNoIGxvZyBtZXNzYWdlc1xuXG5TZXRzIHRoZSBKU09OIGZpZWxkIG5hbWUgdG8gZXh0cmFjdCBmcm9tIGVhY2ggQ2xvdWRXYXRjaCBsb2cgbWVzc2FnZS4gV2hlbiBzZXQsIHRoZSBleHRyYWN0b3Igd2lsbCBsb29rIGZvciB0aGlzIGZpZWxkIGluIGVhY2ggbWVzc2FnZSdzIEpTT04gcGF5bG9hZC4gV2hlbiBlbXB0eSwgdGhlIG1lc3NhZ2UgZXh0cmFjdGlvbiBzdGVwIGlzIHNraXBwZWQuICBGb3IgZXhhbXBsZSwgdG8gZXh0cmFjdCB0aGUgJ2xvZycgZmllbGQgZnJvbSBLdWJlcm5ldGVzL0RvY2tlciBsb2dzOiBgYGAgeWFtbCBtZXNzYWdlRmllbGQ6IGxvZyBgYGAgKERlZmF1bHQ6ICkiLAogICAgICAgICAgICAiZGVmYXVsdCIgOiAiIgogICAgICAgICAgfQogICAgICAgIH0sCiAgICAgICAgInJlcXVpcmVkIiA6IFsKICAgICAgICAgICJuYW1lIiwKICAgICAgICAgICJncm91cE5hbWUiLAogICAgICAgICAgInN0cmVhbU5hbWUiCiAgICAgICAgXQogICAgICB9CiAgICB9CiAgfSwKICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogdHJ1ZQp9</template>

```yaml
# 🔟❎ 'run' AWS CloudWatch Logs input configuration

# Configure an AWS CloudWatch Logs event input
# To learn more see https://doc.log10x.com/run/input/analyzer/cloudwatchLogs/

# Set the 10x pipeline to 'run'
tenx: run

# =============================== Dependencies ================================

include: run/modules/input/analyzer/cloudwatchLogs

# ============================ CloudWatch Options =============================

# Multiple CloudWatch inputs can be defined below
cloudwatchLogs:

    # 'name' sets a unique logical name across all pipeline inputs
  - name: CloudwatchLogs
    
    # --------------------------- Connection Options --------------------------

    # 'awsAccessKeyID' sets the AWS access key (e.g. 'AKIAIOSFODNN7EXAMPLE')
    #  To learn more see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html
    awsAccessKeyID: $=TenXEnv.get("AWS_ACCESS_KEY_ID") # (❗ EnvVar REQUIRED)

    # 'awsSecretKey' sets the AWS access secret key  (e.g. 'wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY')
    #  To learn more see: https://docs.aws.amazon.com/general/latest/gr/aws-sec-cred-types.html
    awsSecretKey: $=TenXEnv.get("AWS_SECRET_ACCESS_KEY") # (❗ EnvVar REQUIRED)

    # 'groupName' sets the log group name (e.g., 'my-log-group').
    #  To learn more see: https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-logGroupName
    groupName: "" # (❗ REQUIRED)

    # 'streamName' sets the log stream name (e.g., 'my-log-stream').
    #  To learn more see: https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-logStreamName
    streamName: "" # (❗ REQUIRED)

    # 'awsRegion' sets the region hosting the CloudWatch Logs stream
    #  To learn more see: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html
    awsRegion: $=TenXEnv.get("AWS_DEFAULT_REGION", "us-east-1")

    # ----------------------------- Query Options -----------------------------

    # 'limit' sets the number of documents retrieved with each results page.
    #  To learn more see: https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-limit
    limit: 500

    # 'startFromHead' controls the direction of the search (old <-> new events).
    #  To learn more see: https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-startFromHead
    startFromHead: true

    # 'startTime' sets the start of the time range, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC.
    #  The search includes events with a timestamp equal to or later than this value.
    #  The search excludes events with a timestamp earlier than this value. 
    #  To learn more see: https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-startTime
    startTime: $=now("-240h")

    # 'endTime' sets the end of the time range, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC.
    #  The search excludes events with a timestamp equal to or later than this value.
    #  To learn more see: https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-endTime
    endTime: $=now()

    # --------------------------- Backpressure Options -----------------------

    # 'queryInterval' sets the interval between queries to the remote API
    queryInterval: $=parseDuration("2s")

    # 'totalDuration' sets the max duration to try reading from the the remote input 
    totalDuration: $=parseDuration("5min")

    # 'totalBytesLimit' sets the max total bytes to read from the remote input
    totalBytesLimit: $=parseBytes("50MB")

    # 'totalEventsLimit' sets the max number of events to read the remote input
    totalEventsLimit: 10000

    # --------------------------- Ancillary Options ---------------------------

    # 'printProgress' controls whether to print a gage to the console
    #  This option helps debug and test the input
    printProgress: $=!TenXEnv.get("quiet")

    # 'messageField' sets the JSON field to extract from CloudWatch log messages
    #  For K8s/Docker logs with 10x encoding, use 'log' to extract the encoded log field
    messageField: log
```

## :material-menu: Options

Specify the options below to [configure](/config "configure") multiple AWS Cloudwatch Logs input:

|Name|Description|Category|
|---|---|---|
|[cloudwatchLogsName](#cloudwatchlogsname "logical name for this AWS CloudWatch Logs input")|Logical name for this AWS CloudWatch Logs input|General|
|[cloudwatchLogsEnabled](#cloudwatchlogsenabled "sets whether this input is enabled")|Sets whether this input is enabled|General|
|[cloudwatchLogsPrintProgress](#cloudwatchlogsprintprogress "sets whether this input prints throughput stats to the console")|Sets whether this input prints throughput stats to the console|General|
|[cloudwatchLogsAwsRegion](#cloudwatchlogsawsregion "AWS region")|AWS region|Authentication|
|[cloudwatchLogsAwsAccessKeyID](#cloudwatchlogsawsaccesskeyid "AWS authentication access key ID")|AWS authentication access key ID|Authentication|
|[cloudwatchLogsAwsSecretKey](#cloudwatchlogsawssecretkey "AWS authentication secret key")|AWS authentication secret key|Authentication|
|[cloudwatchLogsGroupName](#cloudwatchlogsgroupname "AWS CloudWatch Logs Group name")|AWS CloudWatch Logs Group name|Log group|
|[cloudwatchLogsStreamName](#cloudwatchlogsstreamname "AWS CloudWatch Logs Stream name")|AWS CloudWatch Logs Stream name|Log group|
|[cloudwatchLogsLimit](#cloudwatchlogslimit "number of events to read per batch from the AWS CloudWatch Logs service")|Number of events to read per batch from the AWS CloudWatch Logs service|Query|
|[cloudwatchLogsNextToken](#cloudwatchlogsnexttoken "The token for the next set of items to return (received this token from a previous call)")|The token for the next set of items to return (received this token from a previous call)|Query|
|[cloudwatchLogsStartFromHead](#cloudwatchlogsstartfromhead "If true, return the earliest log events first. If false, return the most recent log events first.")|If true, return the earliest log events first. If false, return the most recent log events first.|Query|
|[cloudwatchLogsStartTime](#cloudwatchlogsstarttime "The start of the time range, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC.")|The start of the time range, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC.|Query|
|[cloudwatchLogsEndTime](#cloudwatchlogsendtime "The end of the time range, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC")|The end of the time range, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC|Query|
|[cloudwatchLogsRetryTimeout](#cloudwatchlogsretrytimeout "a timeout period (in milliseconds) to wait for querying of new data")|A timeout period (in milliseconds) to wait for querying of new data|Query|
|[cloudwatchLogsTotalBytesLimit](#cloudwatchlogstotalbyteslimit "maximum total bytes to read from input before closing")|Maximum total bytes to read from input before closing|Backpressure|
|[cloudwatchLogsTotalEventsLimit](#cloudwatchlogstotaleventslimit "maximum total events to read from input before closing")|Maximum total events to read from input before closing|Backpressure|
|[cloudwatchLogsTotalDuration](#cloudwatchlogstotalduration "maximum duration to keep input open before closing")|Maximum duration to keep input open before closing|Backpressure|
|[cloudwatchLogsQueryInterval](#cloudwatchlogsqueryinterval "query interval (in milliseconds) for checking new data from remote source")|Query interval (in milliseconds) for checking new data from remote source|Backpressure|
|[cloudwatchLogsMessageField](#cloudwatchlogsmessagefield "JSON field name to extract from CloudWatch log messages")|JSON field name to extract from CloudWatch log messages|Extraction|

### General

#### :material-menu-right-outline:**`cloudwatchLogsName`**

Logical name for this AWS CloudWatch Logs input.

|Type|Required|Category|
|---|---|---|
|String|✔|General|

Sets a logical name (e.g., 'myCloudWatchLogs') for this input.
The [inputName](https://doc.log10x.com/api/js/#TenXBaseObject+inputName "Returns the context in which the current object, template or summary was created.") field
returns this value at run time to allow for identifying and operating on instances originating from this input.


#### :material-menu-right-outline:**`cloudwatchLogsEnabled`**

Sets whether this input is enabled.

|Type|Default|Category|
|---|---|---|
|Boolean|false|General|

Sets whether to open the input stream.
To enable this input only when a 'cloudwatchLogsName' startup argument value is truthy, use:

```yaml
cloudwatchLogsEnabled: $=TenXEnv.get("cloudwatchLogsName")
```

To learn more see [TenXEnv.get](https://doc.log10x.com/api/js/#TenXEnv.get).


#### :material-menu-right-outline:**`cloudwatchLogsPrintProgress`**

Sets whether this input prints throughput stats to the console.

|Type|Default|Category|
|---|---|---|
|Boolean|false|General|

Sets whether this input prints throughput stats to the console
for testing an integration to a remote endpoint.


### Authentication

#### :material-menu-right-outline:**`cloudwatchLogsAwsRegion`**

AWS region.

|Type|Default|Category|
|---|---|---|
|String|""|Authentication|

Sets the AWS region (e.g., 'us-east-1') hosting
the target CloudWatch logs stream.

To learn more see [AWS Regions](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html){target="\_blank"}.


#### :material-menu-right-outline:**`cloudwatchLogsAwsAccessKeyID`**

AWS authentication access key ID.

|Type|Default|Category|
|---|---|---|
|String|""|Authentication|

Sets the AWS access key (e.g., 'AKIAIOSFODNN7EXAMPLE')
used as part of the request signing process.

**If not specified**, the system automatically falls back to the
[AWS default credential provider chain](https://docs.aws.amazon.com/sdk-for-java/latest/developer-guide/credentials-chain.html){target="\_blank"},
which checks (in order):

1. Environment variables (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`)
2. Java system properties
3. Web identity token (for EKS)
4. Shared credentials file (`~/.aws/credentials`)
5. ECS container credentials
6. EC2 instance profile credentials

To learn more see [AWS access keys](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html){target="\_blank"}.


#### :material-menu-right-outline:**`cloudwatchLogsAwsSecretKey`**

AWS authentication secret key.

|Type|Default|Category|
|---|---|---|
|String|""|Authentication|

Sets the AWS access secret key
(e.g. 'wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY') used as part of the request signing process.

**If not specified**, the system automatically falls back to the
[AWS default credential provider chain](https://docs.aws.amazon.com/sdk-for-java/latest/developer-guide/credentials-chain.html){target="\_blank"}.
This allows using credentials from `~/.aws/credentials`, IAM roles, or environment variables
without explicit configuration.

To learn more see [AWS security credentials](https://docs.aws.amazon.com/general/latest/gr/aws-sec-cred-types.html){target="\_blank"}.


### Log group

#### :material-menu-right-outline:**`cloudwatchLogsGroupName`**

AWS CloudWatch Logs Group name.

|Type|Required|Category|
|---|---|---|
|String|✔|Log group|

Used within the body of the 'GetLogEvents' AWS request
to specify the log group name (e.g., 'my-log-group').

To learn more see [logGroupName](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-logGroupName){target="\_blank"}.


#### :material-menu-right-outline:**`cloudwatchLogsStreamName`**

AWS CloudWatch Logs Stream name.

|Type|Required|Category|
|---|---|---|
|String|✔|Log group|

Used within the body of the AWS 'AGetLogEvents' request
to specify the log stream name (e.g., 'my-log-stream').

To learn more see [logStreamName](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-logStreamName){target="\_blank"}.


### Query

#### :material-menu-right-outline:**`cloudwatchLogsLimit`**

Number of events to read per batch from the AWS CloudWatch Logs service.

|Type|Default|Category|
|---|---|---|
|Number|500|Query|

Sets the number of documents to retrieve with
each page of results. To learn more see: [request limit](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-limit){target="\_blank"}.


#### :material-menu-right-outline:**`cloudwatchLogsNextToken`**

The token for the next set of items to return (received this token from a previous call).

|Type|Default|Category|
|---|---|---|
|String|""|Query|

Sets the token from which the requested result page is to start. This value is
returned from a previous call to the AWS 'GetLogEvents' command.
To learn more see: [nextToken](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-nextToken){target="\_blank"}.


#### :material-menu-right-outline:**`cloudwatchLogsStartFromHead`**

If true, return the earliest log events first. If false, return the most recent log events first.

|Type|Default|Category|
|---|---|---|
|Boolean|false|Query|

Controls the direction of the search (old \<-\> new events).
By default, the search starts from the most recent events. To learn more see: [startFromHead](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-startFromHead){target="\_blank"}.


#### :material-menu-right-outline:**`cloudwatchLogsStartTime`**

The start of the time range, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC.

|Type|Default|Category|
|---|---|---|
|Number|0|Query|

Sets the start of the time range, expressed as milliseconds after Jan 1, 1970 00:00:00 UTC.
Events with a timestamp equal to this time or later than this time are included.
Events with a timestamp earlier than this time are excluded:
To learn more see: [startTime](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-startTime){target="\_blank"}.


#### :material-menu-right-outline:**`cloudwatchLogsEndTime`**

The end of the time range, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC.

|Type|Default|Category|
|---|---|---|
|Number|0|Query|

Sets the end of the time range, expressed as milliseconds after Jan 1, 1970 00:00:00 UTC.
Events with a timestamp equal to or later than this time are not included:
To learn more see: [endTime](https://docs.aws.amazon.com/AmazonCloudWatchLogs/latest/APIReference/API_GetLogEvents.html#CWL-GetLogEvents-request-endTime){target="\_blank"}.


#### :material-menu-right-outline:**`cloudwatchLogsRetryTimeout`**

A timeout period (in milliseconds) to wait for querying of new data.

|Type|Default|Category|
|---|---|---|
|Number|20000|Query|

Used by [cloudwatchLogs-input.js](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/analyzer/cloudwatchLogs/cloudwatchLogs-input.js){target="\_blank"} to determine how long to wait
to invoke the 'GetLogEvents' API again to query for new data.


### Backpressure

#### :material-menu-right-outline:**`cloudwatchLogsTotalBytesLimit`**

Maximum total bytes to read from input before closing.

|Type|Default|Category|
|---|---|---|
|Number|50000000|Backpressure|

sets the maximum number of bytes a target pipeline input will read into the pipeline.
This value limits the volume of events to read from a local/remote source (e.g., log analyzer).

For example:

```yaml
totalBytesLimit: $=parseBytes("1GB")
```


#### :material-menu-right-outline:**`cloudwatchLogsTotalEventsLimit`**

Maximum total events to read from input before closing.

|Type|Default|Category|
|---|---|---|
|Number|10000|Backpressure|

Sets the maximum number of events a target pipeline input will read into the pipeline.
This value limits the volume of events to read from a local/remote source (e.g., log analyzer).


#### :material-menu-right-outline:**`cloudwatchLogsTotalDuration`**

Maximum duration to keep input open before closing.

|Type|Default|Category|
|---|---|---|
|String|parseDuration("5min")|Backpressure|

sets the maximum duration a target pipeline input will remain open.
When reached, the input will close and no more data will be read.

For example:

```yaml
cloudwatchLogsTotalDuration: $=parseDuration("10min")
```


#### :material-menu-right-outline:**`cloudwatchLogsQueryInterval`**

Query interval (in milliseconds) for checking new data from remote source.

|Type|Default|Category|
|---|---|---|
|Number|2000|Backpressure|

sets the interval between queries to the remote CloudWatch Logs API.
This controls how frequently the input polls for new log data.

For example:

```yaml
cloudwatchLogsQueryInterval: $=parseDuration("5s")
```


### Extraction

#### :material-menu-right-outline:**`cloudwatchLogsMessageField`**

JSON field name to extract from CloudWatch log messages.

|Type|Default|Category|
|---|---|---|
|String||Extraction|

sets the JSON field name to extract from each CloudWatch log message.
When set, the extractor will look for this field in each message's JSON payload.
When empty, the message extraction step is skipped.

For example, to extract the 'log' field from Kubernetes/Docker logs:

```yaml
messageField: log
```


<br/>:material-github: This module is defined in [cloudwatchLogs/module.yaml](https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/analyzer/cloudwatchLogs/module.yaml "cloudwatchLogs/module.yaml"){target="\_blank"}.

