You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Java SDK:为Lambda指定自定义日志组及资源政策配置求助

How to Pre-Create a CloudWatch Log Group and Assign It to Lambda with Resource Policy

Hey there, let's walk through exactly how to set this up—pre-creating your CloudWatch Logs group, configuring the resource policy to let Lambda write to it, and linking it to your Lambda function properly.

1. First, Create Your Target CloudWatch Log Group

  • Head to the CloudWatch Console → Logs → Log groups → Click "Create log group"
  • Name it something like /aws/lambda/your-function-name (you can use any name, but following the standard prefix keeps things organized)
  • Set your preferred retention period (optional but recommended to avoid unnecessary log storage costs)

2. Configure the Resource Policy for CloudWatch Logs

This is the key piece you're asking about—this policy grants Lambda explicit permission to write logs to your pre-created group. Here are two ways to set it up:

Option 1: Using the AWS CLI

Run this command, replacing the placeholders with your actual AWS details:

aws logs put-resource-policy \
  --policy-name "LambdaWriteToPreCreatedLogGroup" \
  --policy-document '{
    "Version": "2012-10-17",
    "Statement": [
      {
        "Effect": "Allow",
        "Principal": {
          "Service": "lambda.amazonaws.com"
        },
        "Action": [
          "logs:CreateLogStream",
          "logs:PutLogEvents"
        ],
        "Resource": "arn:aws:logs:REGION:ACCOUNT_ID:log-group:YOUR_LOG_GROUP_NAME:*"
      }
    ]
  }'
  • Swap REGION with your AWS region (e.g., us-east-1)
  • Replace ACCOUNT_ID with your 12-digit AWS account ID
  • Change YOUR_LOG_GROUP_NAME to the exact name of the log group you created earlier

Option 2: Using the CloudWatch Console

  • Go to CloudWatch → Logs → Log groups → Select your pre-created group → Click "Actions" → "Edit resource policy"
  • Paste the same JSON policy from the CLI example (adjusting placeholders) and save the changes

Now you need to tell Lambda to use your custom log group instead of auto-creating a new one:

Using the AWS CLI

aws lambda update-function-configuration \
  --function-name YOUR_LAMBDA_FUNCTION_NAME \
  --environment Variables="{AWS_LAMBDA_LOG_GROUP_NAME=YOUR_LOG_GROUP_NAME}"

Using the Lambda Console

  • Navigate to Lambda → Your function → Configuration → Environment variables → Click "Edit"
  • Add a new environment variable with key AWS_LAMBDA_LOG_GROUP_NAME and value equal to your pre-created log group name
  • Save the changes

4. Verify the Setup

  • Invoke your Lambda function (either via the console, CLI, or your trigger)
  • Check your pre-created log group in CloudWatch—you should see new log streams and events appearing there
  • Confirm no new log group was created automatically (Lambda will skip auto-creation if it's explicitly told to use your custom group)

A quick sanity check: Make sure your Lambda execution role also has the logs:CreateLogStream and logs:PutLogEvents permissions. This is usually included in the default Lambda execution policy, but double-check if you've customized the role's permissions.

内容的提问来源于stack exchange,提问作者Kousha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:19:00