Already running the CloudFormation stack?
You already have both streams described here, better-stack-logs and better-stack-metrics. There is nothing to create.
Send logs and CloudWatch metrics to Better Stack through Amazon Data Firehose, formerly Kinesis Data Firehose.
Bring your own Firehose streams when the Better Stack CloudFormation stack isn't an option for you, for example because of your account's IAM policy.
You already have both streams described here, better-stack-logs and better-stack-metrics. There is nothing to create.
Create a new AWS source in Better Stack. One source can receive both logs and metrics.
Logs and metrics use different Better Stack endpoints, and a Firehose stream has one destination. Create a stream for logs, a stream for metrics, or just the one you need.
In AWS Console β Amazon Data Firehose β Firehose streams, click Create Firehose stream and use these settings:
Keep the remaining settings at their defaults:
The IAM role the console just created hasn't propagated yet. Wait a few seconds and press Create Firehose stream again.
For the logs stream, run Test with demo data on the stream's detail page to check the connection. The demo records show up in Live tail within a few minutes. Skip it for the metrics stream. The demo records are not CloudWatch metrics and are discarded.
Forward a log group to your logs stream with a subscription filter:
logs.amazonaws.com with the policy below, replacing the region and account ID.Each log event arrives in Better Stack as a separate log with the log group and log stream names as context. Repeat the steps for every log group you want to forward. They can all share one Firehose stream.
To give log groups different retention periods, send them to separate sources through separate streams. If you use the CloudFormation stack, follow Custom log group routing.
Anything that writes JSON records to a Firehose stream works the same way, such as Fluent Bit's kinesis_firehose output on AWS Fargate or AWS WAF logs.
A CloudWatch metric stream delivers every metric update in a region to your metrics Firehose stream within a few minutes.
The console preselects the OpenTelemetry 1.0 format for custom Firehose setups. Better Stack ingests the JSON format only. Metrics streamed in an OpenTelemetry format are discarded. Switch an existing metric stream to JSON from its Edit page at any time.
Your metrics appear in Dashboards within a few minutes. To watch the Firehose stream itself, create a dashboard from the AWS Firehose template.
Metrics are converted to Better Stack naming. For example, AWS/EC2/CPUUtilization becomes aws.ec2.cpu_utilization, with its dimensions as tags such as instance_id. The CloudWatch statistics are available as aws.ec2.cpu_utilization_min, _max, _sum and _count.
us-east-1. Create the metric stream there to collect them.To trade latency for a lower bill, the CloudFormation stack can poll your metrics through the CloudWatch API instead.
Prefer infrastructure as code? Each template creates the Firehose stream, its backup bucket and IAM roles, plus the producer - a subscription filter for one log group, or a metric stream with the output format set to JSON. Deploy them in each region you want to collect from.
Deploy with the AWS CLI:
Open the stream's Monitoring tab for the HTTP endpoint delivery success rate and the Destination error logs tab for rejected deliveries. Batches that failed for longer than the retry duration end up in the backup bucket under the error output prefix. For metrics, also check that the metric stream's output format is JSON.
Better Stack rejected the request. The usual cause is an access key that doesn't match your source token. A paused source or an exceeded quota are the other reasons. Fix the cause and Firehose retries the pending batches on its own.
Firehose streams can't be paused. Stop the metric stream in CloudWatch β Metrics β Streams, or delete the subscription filter on a log group. Delivery resumes when you start it again.
To remove the integration, delete the metric stream and the subscription filters first, then the Firehose streams, the IAM roles, and the backup bucket after emptying it.
Please let us know at hello@betterstack.com.
We're happy to help! π
We use cookies to authenticate users, improve the product user experience, and for personalized ads. Learn more.