AWS Fundamentals Logo
AWS Fundamentals
logs:*

AWS Amazon CloudWatch Logs IAM Actions

122 IAM actions for logs:*

Actions

122 actions available. Filter by access level or search by name.

Filter:
ActionAccess Level
logs:AssociateKmsKey
Write
logs:AssociateSourceToS3TableIntegration
Write
logs:CallWithBearerToken
Read
logs:CancelExportTask
Write
logs:CancelImportTask
Write
logs:CreateDelivery
Write
logs:CreateExportTask
Write
logs:CreateImportTask
Write
logs:CreateLogAnomalyDetector
Write
logs:CreateLogDelivery
Write
logs:CreateLogGroup
Write
logs:CreateLogStream
Write
logs:CreateScheduledQuery
Write
logs:DeleteAccountPolicy
Permissions
logs:DeleteDataProtectionPolicy
Permissions
logs:DeleteDelivery
Write
logs:DeleteDeliveryDestination
Write
logs:DeleteDeliveryDestinationPolicy
Permissions
logs:DeleteDeliverySource
Write
logs:DeleteDestination
Write
logs:DeleteIndexPolicy
Permissions
logs:DeleteIntegration
Write
logs:DeleteLogAnomalyDetector
Write
logs:DeleteLogDelivery
Write
logs:DeleteLogGroup
Write
logs:DeleteLogStream
Write
logs:DeleteMetricFilter
Write
logs:DeletePipelineRule
Write
logs:DeleteQueryDefinition
Write
logs:DeleteResourcePolicy
Permissions
logs:DeleteRetentionPolicy
Permissions
logs:DeleteScheduledQuery
Write
logs:DeleteSubscriptionFilter
Write
logs:DeleteTransformer
Write
logs:DescribeAccountPolicies
Read
logs:DescribeConfigurationTemplates
Read
logs:DescribeDeliveries
Read
logs:DescribeDeliveryDestinations
Read
logs:DescribeDeliverySources
Read
logs:DescribeDestinations
Read
logs:DescribeExportTasks
Read
logs:DescribeFieldIndexes
Read
logs:DescribeImportTaskBatches
Read
logs:DescribeImportTasks
Read
logs:DescribeIndexPolicies
Read
logs:DescribeLogGroups
Read
logs:DescribeLogStreams
Read
logs:DescribeMetricFilters
Read
logs:DescribeQueries
Read
logs:DescribeQueryDefinitions
Read
logs:DescribeResourcePolicies
Read
logs:DescribeSubscriptionFilters
Read
logs:DisassociateKmsKey
Write
logs:DisassociateSourceFromS3TableIntegration
Write
logs:FilterLogEvents
Read
logs:GetDataProtectionPolicy
Permissions
logs:GetDelivery
Read
logs:GetDeliveryDestination
Read
logs:GetDeliveryDestinationPolicy
Permissions
logs:GetDeliverySource
Read
logs:GetIntegration
Read
logs:GetLogAnomalyDetector
Read
logs:GetLogDelivery
Read
logs:GetLogEvents
Read
logs:GetLogFields
Read
logs:GetLogGroupFields
Read
logs:GetLogRecord
Read
logs:GetQueryResults
Read
logs:GetScheduledQuery
Read
logs:GetScheduledQueryHistory
Read
logs:GetTransformer
Read
logs:IntegrateWithS3Table
Read
logs:Link
Read
logs:ListAggregateLogGroupSummaries
Tagging
logs:ListAnomalies
List
logs:ListEntitiesForLogGroup
List
logs:ListIntegrations
List
logs:ListLogAnomalyDetectors
List
logs:ListLogDeliveries
List
logs:ListLogGroups
List
logs:ListLogGroupsForEntity
List
logs:ListLogGroupsForQuery
List
logs:ListScheduledQueries
List
logs:ListSourcesForS3TableIntegration
List
logs:ListTagsForResource
Tagging
logs:ListTagsLogGroup
Tagging
logs:ProcessWithPipeline
Read
logs:PutAccountPolicy
Permissions
logs:PutBearerTokenAuthentication
Write
logs:PutDataProtectionPolicy
Permissions
logs:PutDeliveryDestination
Write
logs:PutDeliveryDestinationPolicy
Permissions
logs:PutDeliverySource
Write
logs:PutDestination
Write
logs:PutDestinationPolicy
Permissions
logs:PutIndexPolicy
Permissions
logs:PutIntegration
Write
logs:PutLogEvents
Write
logs:PutLogGroupDeletionProtection
Write
logs:PutMetricFilter
Write
logs:PutPipelineRule
Write
logs:PutQueryDefinition
Write
logs:PutResourcePolicy
Permissions
logs:PutRetentionPolicy
Permissions
logs:PutSubscriptionFilter
Write
logs:PutTransformer
Write
logs:StartLiveTail
Write
logs:StartQuery
Write
logs:StopLiveTail
Write
logs:StopQuery
Write
logs:TagLogGroup
Tagging
logs:TagResource
Tagging
logs:TestMetricFilter
Read
logs:TestTransformer
Read
logs:Unmask
Read
logs:UntagLogGroup
Tagging
logs:UntagResource
Tagging
logs:UpdateAnomaly
Write
logs:UpdateDeliveryConfiguration
Write
logs:UpdateLogAnomalyDetector
Write
logs:UpdateLogDelivery
Write
logs:UpdateScheduledQuery
Write

Resource Types

ARN patterns for resources in this service.

ResourceARN Pattern
.+arn:aws:logs:${Region}:${Account}:.+

Condition Keys

Condition keys you can use in IAM policy conditions for this service.

aws:RequestTag/${TagKey}aws:ResourceTag/${TagKey}aws:TagKeyslogs:DeliveryDestinationResourceArnlogs:LogGeneratingResourceArns

Get the Amazon CloudWatch Logs Cheat Sheet

Everything you need to know about Amazon CloudWatch Logs on one page. HD quality, print-friendly.

Download Free Infographic

Get the Amazon CloudWatch Logs Cheat Sheet

Everything you need to know about Amazon CloudWatch Logs on one page. HD quality, print-friendly.

Download Free Infographic

Quick Facts

Total Actions122
Prefixlogs
Resource Types1
Condition Keys5

Access Level Breakdown

Read
40
Write
50
List
10
Permissions
15
Tagging
7