Amazon CloudWatch Logs supports managed syslog ingestion

Amazon CloudWatch Logs Managed Syslog Ingestion
Amazon CloudWatch Logs now supports managed syslog ingestion, allowing customers to send syslog messages from various devices directly into CloudWatch Logs. This feature enables sending syslog messages over TCP, TCP+TLS, or UDP to a VPC endpoint without managing agents.
Key features include:
- Support for RFC 5424, RFC 3164, and Cisco FTD/ASA syslog formats.
- Automatic parsing of incoming syslog messages to extract structured fields.
- Centralized log visibility for easier security event investigation and troubleshooting.
What to do
- Configure network devices and servers to send syslog messages to a VPC endpoint.
- Use Logs Analytics to query syslog messages by severity or hostname.
- Refer to the Amazon CloudWatch Logs documentation for setup instructions.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



