Chapter 14: Logging and Light Observability
14.4 Primary path — CloudWatch Logs
This course's primary logging path for cloud labs: ship or query logs with Amazon CloudWatch Logs when you practise on AWS.
Why pick CloudWatch here?
- Students already use AWS for VMs in the companion course.
- One account console covers metrics (ch13 secondary mention) and logs.
- You learn the universal idea: central store + search + retention — transferable to other stacks.
ELK briefly (secondary): Elasticsearch + Logstash/Beats + Kibana (or OpenSearch variants) is a popular self-managed/searchable stack many companies still run. Same mental model: agents ship logs → index → search UI. We do not dual-build ELK and CloudWatch in this chapter — pick CloudWatch for the lab pathway; know ELK exists for interviews.
We do not invent CloudWatch pricing, free-tier quotas or retention defaults. Read current AWS documentation for limits and cost behaviour; stop idle labs.
App / Docker / journal
│ ship or agent
▼
CloudWatch Log Group → Log Streams
│
▼
Filter / Logs Insights query → incident note