CloudWatch Alarm example
In the CloudWatch Management Console, go to Metrics → Alarms → Create alarm. When creating an alarm you select the metric and any dimensions (for example, the model or namespace) that you want to watch.
- Namespace: AWS Bedrock
- Metric:
InputTokenCountfor the model Meta Llama 3 8B Instruct - Statistic: 5-minute average
- Condition: trigger when the metric is greater than
8000
Alarms can be as simple or sophisticated as you need. Start with a conservative static threshold to reduce noise, then refine the alarm using anomaly detection or composite alarms as patterns emerge.
Quick steps to create a CloudWatch alarm
- Open CloudWatch → Metrics → choose the Bedrock namespace.
- Select the metric and any dimensions (model, region).
- Click Create alarm → define the statistic (e.g., 5-minute average).
- Set the threshold and evaluation period (e.g., > 8000 for 5 minutes).
- Choose actions (SNS, Lambda, Systems Manager, or none).
- Review and create the alarm.
Bedrock model invocation logging vs application logging
When building Bedrock-based applications, consider two logging layers:
Both layers are important: Bedrock invocation logs record exactly what the Bedrock Runtime received and returned, while your application logs add context (user ID, transaction ID, processing stage) that helps operators troubleshoot and correlate events.
Bedrock Model Invocation Logging is disabled by default. When you enable it in the Bedrock settings you choose:
- Destination: Amazon S3, CloudWatch Logs, or both
- Data types to capture: text, images, embeddings, video
- An IAM service role that grants Bedrock permission to write to the destination
Enabling Bedrock model invocation logging records the full request and model response (input and output). Ensure you have appropriate data handling, retention, and access controls in place before enabling this feature.
model-invocations. We also specify an IAM role that gives Bedrock permission to write into CloudWatch Logs.

Viewing Bedrock invocation logs in CloudWatch Logs
After enabling Bedrock invocation logging to CloudWatch Logs, go to CloudWatch → Logs → Log groups. You will see a log group (for example,model-invocations) that Bedrock writes to. Log events appear as timestamped messages. Example log lines:
Best practices and operational tips
- Minimize sensitive data in inputs if possible; redact or tokenise before sending.
- Use application logs to add context (user IDs, transaction IDs) that are not present in model invocation logs.
- Retention: set CloudWatch Logs retention policies to meet your compliance and cost objectives.
- Automate: attach alarms to SNS or Lambda to shorten detection-to-remediation time.
- Monitor token-based metrics (InputTokenCount, OutputTokenCount) to understand cost and usage patterns.
Links and references
- Amazon CloudWatch documentation
- Amazon Bedrock documentation
- IAM roles for service integrations
- CloudWatch Logs retention and management