- CloudWatch Logs expects event timestamps in milliseconds since the epoch.
- When appending to an existing log stream, CloudWatch requires the correct
sequenceToken(upload sequence token). If the stream is new, create the log group and log stream before callingput_log_events. - Your application needs IAM permissions like
logs:CreateLogGroup,logs:CreateLogStream,logs:PutLogEvents, and optionallylogs:DescribeLogStreams. - On EC2, attach an IAM role (instance profile) to the instance so your code can use temporary credentials automatically. For hosts outside AWS, provide programmatic credentials (access key/secret key) with minimal necessary scope.

- This sample shows the common sequence:
- Ensure the log group and log stream exist.
- Query the upload sequence token (if any).
- Call
put_log_events. - Handle
InvalidSequenceTokenException/DataAlreadyAcceptedExceptionby refetching the token and retrying once.
Grant the required IAM permissions to the identity used by your code: typically
logs:CreateLogGroup, logs:CreateLogStream, logs:DescribeLogStreams, and logs:PutLogEvents. On EC2, prefer an instance profile (IAM role); if running outside AWS, use short-lived credentials and scope them narrowly.- Choose based on where compute runs, privacy/governance needs, and credential provisioning.
Links and references
- Amazon Elastic Compute Cloud (EC2) documentation
- AWS Lambda documentation
- Amazon CloudWatch Logs documentation
- Boto3 (AWS SDK for Python) docs

- For AWS Lambda: write to stdout/stderr and ensure the execution role has logging permissions; CloudWatch capture is automatic.
- For EC2 / VMs: either run a log shipping agent or have the app call CloudWatch Logs APIs directly; use instance roles to avoid long-lived credentials.
- For external hosts: use programmatic credentials scoped to only the required CloudWatch permissions and rotate them regularly.
- For Bedrock-level tracing: enable model invocation logging in the Bedrock service when you need centralized model I/O capture — but review privacy and governance requirements before enabling.