> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Using Amazon CloudWatch With Bedrock Part 5

> Guides enabling and analyzing Amazon Bedrock model invocation logs in CloudWatch, querying with Logs Insights, and correlating those logs with application logs such as AWS Lambda.

This lesson demonstrates how to enable and inspect Amazon Bedrock model invocation logging using Amazon CloudWatch and CloudWatch Logs Insights. You'll learn where invocation records are configured, how to find them in CloudWatch, how to query and visualize them with Logs Insights, and how to correlate Bedrock model logs with application logs (for example, from AWS Lambda).

## 1) Enable model invocation logging in Bedrock

In the Bedrock console Settings you can enable Model Invocation Logging and choose which data types to record (text, image, embeddings, video, etc.). You also pick the destination (for example, CloudWatch Logs) and the log group that will receive those records.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/tDsOIcBSOgU8BE1P/images/Introduction-to-Amazon-Bedrock/Monitoring-and-Logging/Using-Amazon-CloudWatch-With-Bedrock-Part-5/bedrock-settings-model-logging-cloudwatch.jpg?fit=max&auto=format&n=tDsOIcBSOgU8BE1P&q=85&s=461158e14ea48a9f96003cd2b5e96ef1" alt="A screenshot of the AWS Management Console showing the Amazon Bedrock &#x22;Settings&#x22; page, specifically the Model invocation logging section with options for logging data types and CloudWatch Logs selected. The left sidebar shows Bedrock navigation items like Infer, Tune, Build, and Assess." width="1920" height="1080" data-path="images/Introduction-to-Amazon-Bedrock/Monitoring-and-Logging/Using-Amazon-CloudWatch-With-Bedrock-Part-5/bedrock-settings-model-logging-cloudwatch.jpg" />
</Frame>

Tip: enable only the data types you need and follow your organization's security and privacy guidance—model inputs/outputs can contain sensitive data.

<Callout icon="warning" color="#FF6B6B">
  Model invocation logs can capture user input and model output. Ensure your logging configuration and retention policies comply with privacy, regulatory, and security requirements.
</Callout>

## 2) Locate the Bedrock log group in CloudWatch

Open the CloudWatch console and use Log Management (Log groups) to find the log group you configured for Bedrock model invocations.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/tDsOIcBSOgU8BE1P/images/Introduction-to-Amazon-Bedrock/Monitoring-and-Logging/Using-Amazon-CloudWatch-With-Bedrock-Part-5/aws-cloudwatch-bedrock-log-groups.jpg?fit=max&auto=format&n=tDsOIcBSOgU8BE1P&q=85&s=8afedf1b3e60cbe98e2339b24ebbd985" alt="A screenshot of the AWS CloudWatch Log Management console showing a search for &#x22;bedrock&#x22; with several log group entries listed (e.g., /aws/lambda/bedrock-simple-generation). The CloudWatch sidebar and top navigation are visible along with action buttons like &#x22;Create log group&#x22; and &#x22;View in Logs Insights.&#x22;" width="1920" height="1080" data-path="images/Introduction-to-Amazon-Bedrock/Monitoring-and-Logging/Using-Amazon-CloudWatch-With-Bedrock-Part-5/aws-cloudwatch-bedrock-log-groups.jpg" />
</Frame>

Choose the appropriate log group (for example, `kodekloud/bedrock/modelinvocations`) and open it to see its log streams.

## 3) Inspect log streams and events

Log streams behave like rotated log files; CloudWatch creates new streams periodically or when thresholds are reached. Click the most recent log stream to view individual events.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/tDsOIcBSOgU8BE1P/images/Introduction-to-Amazon-Bedrock/Monitoring-and-Logging/Using-Amazon-CloudWatch-With-Bedrock-Part-5/aws-cloudwatch-kodekloud-modelinvocations-logs.jpg?fit=max&auto=format&n=tDsOIcBSOgU8BE1P&q=85&s=2acea9f3f132ed61ed2ddc7e3592859f" alt="A screenshot of the AWS CloudWatch console showing the &#x22;kodekloud/bedrock/modelinvocations&#x22; log group details page with ARN, creation time, retention, stored bytes and a log streams section. The left sidebar shows AWS monitoring navigation (Logs, Metrics, Infrastructure Monitoring, etc.)." width="1920" height="1080" data-path="images/Introduction-to-Amazon-Bedrock/Monitoring-and-Logging/Using-Amazon-CloudWatch-With-Bedrock-Part-5/aws-cloudwatch-kodekloud-modelinvocations-logs.jpg" />
</Frame>

<Callout icon="lightbulb" color="#1CB2FE">
  When inspecting log streams, first set the CloudWatch time range (top-right) to the period you expect activity. Viewing the wrong time window is a common cause of "missing" logs.
</Callout>

## ModelInvocationLog schema — example JSON

A single model invocation entry (schema type `ModelInvocationLog`) contains fields such as timestamp, accountId, region, requestId, operation, modelId, input payload, output payload, usage metrics, and identity. Example:

```json theme={null}
{
  "timestamp": "2026-06-10T14:53:46Z",
  "accountId": "485186561655",
  "region": "us-east-1",
  "requestId": "93dec02f-fc30-46f8-9218-577326e98510",
  "operation": "ConverseStream",
  "modelId": "amazon.nova-pro-v1:0",
  "input": {
    "inputContentType": "application/json",
    "inputBodyJson": {
      "messages": [
        {
          "role": "user",
          "content": [
            {
              "text": "what is the purpose of the context window in a model?"
            }
          ]
        }
      ],
      "inferenceConfig": {
        "maxTokens": 512,
        "temperature": 0.7,
        "topP": 0.9,
        "stopSequences": []
      }
    },
    "inputTokenCount": 12
  },
  "output": {
    "outputContentType": "application/json",
    "outputBodyJson": {
      "output": [
        {
          "message": {
            "role": "assistant",
            "content": [
              {
                "text": "The context window in a model, particularly in the context of natural language processing (NLP) and large language models (LLMs), serves several important purposes: ... (truncated)"
              }
            ]
          }
        }
      ]
    }
  },
  "identity": {
    "arn": "arn:aws:iam::485186561655:user/AlistairS"
  },
  "schemaType": "ModelInvocationLog",
  "schemaVersion": "1.0"
}
```

Key fields you’ll commonly use for telemetry and analysis:

| Field | Description | Example extraction |
| - | -: | - |
| `timestamp` | Event time for correlation and ordering | `@timestamp` |
| `modelId` | Which Bedrock model was invoked | `modelId` |
| `requestId` | Unique request identifier for correlation | `requestId` |
| `input.inputBodyJson` | The original input messages / prompt | `input.inputBodyJson.messages[0].content[0].text` |
| `output.outputBodyJson` | Model output shapes (text, outputs array) | `output.outputBodyJson.output[0].message.content[0].text` |
| `usage` / tokens | Billing/usage tokens, where present | `output.outputBodyJson.usage.totalTokens` |
| `output.outputBodyJson.metrics.latencyMs` | Inference latency (if provided) | `output.outputBodyJson.metrics.latencyMs` |
| `identity.arn` | IAM user or role that made the request | `identity.arn` |

Note: actual field paths vary across models and response shapes; Logs Insights can extract nested JSON fields automatically for easier querying.

## 4) Querying with CloudWatch Logs Insights

Logs Insights supports a SQL-like query language for filtering, extracting fields, and aggregating results. Select the Bedrock log group as the query scope, set an appropriate time range (for example, last 12 hours), and run queries.

A simple default query to show recent events:

```sql theme={null}
fields @timestamp, @message
| sort @timestamp desc
| limit 10000
```

Filter to a specific model:

```sql theme={null}
fields @timestamp, modelId, requestId, identity.arn, input.inputBodyJson.messages[0].content[0].text
| filter modelId = "amazon.nova-micro-v1:0"
| sort @timestamp desc
| limit 10000
```

Aggregate examples:

* Count invocations by model in the last 24 hours:

```sql theme={null}
stats count() by modelId
| sort count desc
```

* Average latency (if a `latencyMs` metric exists in `output.outputBodyJson.metrics`):

```sql theme={null}
filter ispresent(output.outputBodyJson.metrics.latencyMs)
| stats avg(output.outputBodyJson.metrics.latencyMs) as avgLatencyMs by modelId
| sort avgLatencyMs desc
```

Logs Insights will automatically parse JSON messages and expose structured fields for filtering, aggregation, and visualization (histograms, time series).

## 5) Correlating Bedrock logs with application logs (example: Lambda)

If your application (for example an AWS Lambda function) calls Bedrock, you can correlate the application logs and the Bedrock ModelInvocationLog entries using timestamps and request IDs. Lambda writes its own logs to CloudWatch Logs, so both sources will be available in CloudWatch.

Below is a concise Python Lambda example using boto3 to call Bedrock, log the request/response, and extract textual content from common Bedrock response shapes:

```python theme={null}
import json
import logging
import boto3

# Configure logging
logger = logging.getLogger()
logger.setLevel(logging.INFO)

bedrock = boto3.client("bedrock-runtime")  # Bedrock runtime client

def _extract_text_from_body(data):
    """
    Try a few common Bedrock response shapes to find the assistant text.
    This is conservative and looks for common keys like 'outputs', 'content', and 'text'.
    """
    if isinstance(data, dict):
        # Common shape: {"outputs":[{"content":[{"text": "..."}]}]}
        outputs = data.get("outputs")
        if isinstance(outputs, list) and outputs:
            first = outputs[0]
            if isinstance(first, dict):
                content = first.get("content")
                if isinstance(content, list) and content:
                    for c in content:
                        if isinstance(c, dict) and "text" in c:
                            return c["text"]
                if "text" in first:
                    return first["text"]

        # Recursive search for a 'text' key
        for v in data.values():
            t = _extract_text_from_body(v)
            if t:
                return t

    elif isinstance(data, list):
        for item in data:
            t = _extract_text_from_body(item)
            if t:
                return t

    return None

def lambda_handler(event, context):
    logger.info("Lambda function started")
    logger.info("Received event: %s", json.dumps(event))

    try:
        logger.info("BEDROCK_REQUEST: Calling model")

        payload = {
            "messages": [
                {
                    "role": "user",
                    "content": [{"text": "In one sentence, explain what AWS Lambda is."}]
                }
            ],
            "inferenceConfig": {"maxTokens": 256}
        }

        response = bedrock.invoke_model(
            modelId="amazon.nova-micro-v1:0",
            contentType="application/json",
            accept="application/json",
            body=json.dumps(payload)
        )

        # Read the streaming body and parse JSON
        raw_body = response["body"].read().decode("utf-8")
        try:
            body_json = json.loads(raw_body)
        except Exception:
            # If the model returns plain text, fall back to raw_body
            body_json = raw_body

        # Extract the textual answer using helper
        answer = _extract_text_from_body(body_json) if isinstance(body_json, (dict, list)) else str(body_json)

        if not answer:
            answer = "(no textual answer found in model response)"

        logger.info("BEDROCK_RESPONSE: %s", answer)

        return {
            "statusCode": 200,
            "body": answer
        }

    except Exception:
        logger.exception("BEDROCK_ERROR")
        return {
            "statusCode": 500,
            "body": "Error calling Amazon Bedrock"
        }
```

When you test this Lambda, CloudWatch Logs will contain:

* Lambda execution logs (INFO / ERROR lines from your handler)
* Bedrock ModelInvocationLog entries in the configured Bedrock log group

Use timestamps and `requestId` values to correlate individual Lambda runs with their corresponding ModelInvocationLog for troubleshooting and latency analysis.

Example Lambda output (HTTP-like response):

```json theme={null}
{
  "statusCode": 200,
  "body": "AWS Lambda is a serverless computing service that enables you to run code without provisioning or managing servers."
}
```

And a sample Lambda execution log excerpt:

```console theme={null}
[INFO] 2026-06-10T15:03:30.994Z Lambda function started
[INFO] 2026-06-10T15:03:30.994Z Received event: {"key1": "value1", "key2": "value2", "key3": "value3"}
[INFO] 2026-06-10T15:03:31.095Z BEDROCK_REQUEST: Calling model
[INFO] 2026-06-10T15:03:31.617Z BEDROCK_RESPONSE: AWS Lambda is a serverless computing service that enables you to run code without provisioning or managing servers.
REPORT RequestId: d69c4842-3429-414d-ad89-3f1996e28fcb Duration: 690.08 ms Billed Duration: 1246 ms Memory Size: 128 MB Max Memory Used: 93 MB Init Duration: 555.07 ms
```

## 6) Monitoring at scale

As invocation volume grows, use Logs Insights to:

* Aggregate counts per model (`stats count() by modelId`)
* Detect latency spikes (`avg(latencyMs)`)
* Monitor token usage for cost analysis (`sum(output.outputBodyJson.usage.totalTokens)`)
* Create CloudWatch dashboards and alarms based on query results or extracted metrics

Drill down from aggregated charts into individual ModelInvocationLog events for root cause analysis.

## Links and references

* [Amazon Bedrock documentation](https://docs.aws.amazon.com/bedrock)
* [Amazon CloudWatch Logs Insights](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/AnalyzingLogData.html)
* [boto3 Bedrock Runtime client (invoke\_model)](https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/bedrock-runtime.html)

If you need example Logs Insights queries or a dashboard template for Bedrock metrics, I can provide those tailored to your log schema and retention requirements.

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/introduction-to-amazon-bedrock/module/f66ead5c-d28c-4d82-8daf-c1ca1ebfa7b0/lesson/6d37ec98-07b5-48db-8bb6-d87a92b6809d" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.