Skip to main content
This lesson demonstrates how to enable and inspect Amazon Bedrock model invocation logging using Amazon CloudWatch and CloudWatch Logs Insights. You’ll learn where invocation records are configured, how to find them in CloudWatch, how to query and visualize them with Logs Insights, and how to correlate Bedrock model logs with application logs (for example, from AWS Lambda).

1) Enable model invocation logging in Bedrock

In the Bedrock console Settings you can enable Model Invocation Logging and choose which data types to record (text, image, embeddings, video, etc.). You also pick the destination (for example, CloudWatch Logs) and the log group that will receive those records.
A screenshot of the AWS Management Console showing the Amazon Bedrock "Settings" page, specifically the Model invocation logging section with options for logging data types and CloudWatch Logs selected. The left sidebar shows Bedrock navigation items like Infer, Tune, Build, and Assess.
Tip: enable only the data types you need and follow your organization’s security and privacy guidance—model inputs/outputs can contain sensitive data.
Model invocation logs can capture user input and model output. Ensure your logging configuration and retention policies comply with privacy, regulatory, and security requirements.

2) Locate the Bedrock log group in CloudWatch

Open the CloudWatch console and use Log Management (Log groups) to find the log group you configured for Bedrock model invocations.
A screenshot of the AWS CloudWatch Log Management console showing a search for "bedrock" with several log group entries listed (e.g., /aws/lambda/bedrock-simple-generation). The CloudWatch sidebar and top navigation are visible along with action buttons like "Create log group" and "View in Logs Insights."
Choose the appropriate log group (for example, kodekloud/bedrock/modelinvocations) and open it to see its log streams.

3) Inspect log streams and events

Log streams behave like rotated log files; CloudWatch creates new streams periodically or when thresholds are reached. Click the most recent log stream to view individual events.
A screenshot of the AWS CloudWatch console showing the "kodekloud/bedrock/modelinvocations" log group details page with ARN, creation time, retention, stored bytes and a log streams section. The left sidebar shows AWS monitoring navigation (Logs, Metrics, Infrastructure Monitoring, etc.).
When inspecting log streams, first set the CloudWatch time range (top-right) to the period you expect activity. Viewing the wrong time window is a common cause of “missing” logs.

ModelInvocationLog schema — example JSON

A single model invocation entry (schema type ModelInvocationLog) contains fields such as timestamp, accountId, region, requestId, operation, modelId, input payload, output payload, usage metrics, and identity. Example:
Key fields you’ll commonly use for telemetry and analysis: Note: actual field paths vary across models and response shapes; Logs Insights can extract nested JSON fields automatically for easier querying.

4) Querying with CloudWatch Logs Insights

Logs Insights supports a SQL-like query language for filtering, extracting fields, and aggregating results. Select the Bedrock log group as the query scope, set an appropriate time range (for example, last 12 hours), and run queries. A simple default query to show recent events:
Filter to a specific model:
Aggregate examples:
  • Count invocations by model in the last 24 hours:
  • Average latency (if a latencyMs metric exists in output.outputBodyJson.metrics):
Logs Insights will automatically parse JSON messages and expose structured fields for filtering, aggregation, and visualization (histograms, time series).

5) Correlating Bedrock logs with application logs (example: Lambda)

If your application (for example an AWS Lambda function) calls Bedrock, you can correlate the application logs and the Bedrock ModelInvocationLog entries using timestamps and request IDs. Lambda writes its own logs to CloudWatch Logs, so both sources will be available in CloudWatch. Below is a concise Python Lambda example using boto3 to call Bedrock, log the request/response, and extract textual content from common Bedrock response shapes:
When you test this Lambda, CloudWatch Logs will contain:
  • Lambda execution logs (INFO / ERROR lines from your handler)
  • Bedrock ModelInvocationLog entries in the configured Bedrock log group
Use timestamps and requestId values to correlate individual Lambda runs with their corresponding ModelInvocationLog for troubleshooting and latency analysis. Example Lambda output (HTTP-like response):
And a sample Lambda execution log excerpt:

6) Monitoring at scale

As invocation volume grows, use Logs Insights to:
  • Aggregate counts per model (stats count() by modelId)
  • Detect latency spikes (avg(latencyMs))
  • Monitor token usage for cost analysis (sum(output.outputBodyJson.usage.totalTokens))
  • Create CloudWatch dashboards and alarms based on query results or extracted metrics
Drill down from aggregated charts into individual ModelInvocationLog events for root cause analysis. If you need example Logs Insights queries or a dashboard template for Bedrock metrics, I can provide those tailored to your log schema and retention requirements.

Watch Video