1) Enable model invocation logging in Bedrock
In the Bedrock console Settings you can enable Model Invocation Logging and choose which data types to record (text, image, embeddings, video, etc.). You also pick the destination (for example, CloudWatch Logs) and the log group that will receive those records.
Model invocation logs can capture user input and model output. Ensure your logging configuration and retention policies comply with privacy, regulatory, and security requirements.
2) Locate the Bedrock log group in CloudWatch
Open the CloudWatch console and use Log Management (Log groups) to find the log group you configured for Bedrock model invocations.
kodekloud/bedrock/modelinvocations) and open it to see its log streams.
3) Inspect log streams and events
Log streams behave like rotated log files; CloudWatch creates new streams periodically or when thresholds are reached. Click the most recent log stream to view individual events.
When inspecting log streams, first set the CloudWatch time range (top-right) to the period you expect activity. Viewing the wrong time window is a common cause of “missing” logs.
ModelInvocationLog schema — example JSON
A single model invocation entry (schema typeModelInvocationLog) contains fields such as timestamp, accountId, region, requestId, operation, modelId, input payload, output payload, usage metrics, and identity. Example:
Note: actual field paths vary across models and response shapes; Logs Insights can extract nested JSON fields automatically for easier querying.
4) Querying with CloudWatch Logs Insights
Logs Insights supports a SQL-like query language for filtering, extracting fields, and aggregating results. Select the Bedrock log group as the query scope, set an appropriate time range (for example, last 12 hours), and run queries. A simple default query to show recent events:- Count invocations by model in the last 24 hours:
- Average latency (if a
latencyMsmetric exists inoutput.outputBodyJson.metrics):
5) Correlating Bedrock logs with application logs (example: Lambda)
If your application (for example an AWS Lambda function) calls Bedrock, you can correlate the application logs and the Bedrock ModelInvocationLog entries using timestamps and request IDs. Lambda writes its own logs to CloudWatch Logs, so both sources will be available in CloudWatch. Below is a concise Python Lambda example using boto3 to call Bedrock, log the request/response, and extract textual content from common Bedrock response shapes:- Lambda execution logs (INFO / ERROR lines from your handler)
- Bedrock ModelInvocationLog entries in the configured Bedrock log group
requestId values to correlate individual Lambda runs with their corresponding ModelInvocationLog for troubleshooting and latency analysis.
Example Lambda output (HTTP-like response):
6) Monitoring at scale
As invocation volume grows, use Logs Insights to:- Aggregate counts per model (
stats count() by modelId) - Detect latency spikes (
avg(latencyMs)) - Monitor token usage for cost analysis (
sum(output.outputBodyJson.usage.totalTokens)) - Create CloudWatch dashboards and alarms based on query results or extracted metrics
Links and references
- Amazon Bedrock documentation
- Amazon CloudWatch Logs Insights
- boto3 Bedrock Runtime client (invoke_model)