AWS CLI — Logs & Monitoring Cheat Sheet 2026
AWS CLI Logs & Monitoring Cheat Sheet is the complete quick-reference of AWS CLI Logs & Monitoring commands grouped by function. Copy any command with one click and find what you need with Ctrl+F in under 3 seconds.
Logs & Monitoring
| Action | Command | Useful flags |
|---|---|---|
| List log groups |
|
|
| Continuously poll logs of a CloudWatch log group |
|
--follow |
| Tail the logs of a CloudWatch log group based on a filter |
|
--filter-pattern |
| Stream near real-time logs from a log group |
|
--log-group-identifiers |
| Export logs to an S3 bucket |
|
--log-group-name --from --to --destination |
| List dashboards for your account |
|
|
| Display details for the specified dashboard |
|
--dashboard-name |
| List metrics |
|
|
| List alarms |
|
|
| Create or update an alarm and associate it with a metric |
|
--alarm-name --evaluation-periods --comparison-operator |
| Delete the specified alarms |
|
--alarm-names |
| Delete the specified dashboards |
|
--dashboard-names |
⚠️ Dangerous / Destructive Commands
These commands are irreversible. Verify your environment (dev/staging vs prod) before running them.
| Action | Command | Warning |
|---|---|---|
| ⚠️ Cloudwatch delete-alarms |
|
Irreversible — verify the target before running |
| ⚠️ Cloudwatch delete-dashboards |
|
Irreversible — verify the target before running |
FAQ — Frequently Asked Questions
What is the difference between Logs & Monitoring and the other groups?
Each group in this AWS CLI cheat sheet covers a distinct area. Logs & Monitoring focuses on its specific scope, while the other groups and the remaining groups cover networking, storage, security and diagnostics respectively.
How do I check the installed AWS CLI version?
Run the version command (usually aws version or aws --version). The output shows the client and, when applicable, the server version.
Why does AWS CLI return ‘permission denied’?
A ‘permission denied’ error in AWS CLI usually means the current user lacks sufficient privileges or credentials are not configured. Check: (1) assigned IAM/RBAC roles, (2) an active authentication context via the corresponding login command.
How do I filter AWS CLI output by status or name?
Use flags such as --filter, --selector or --query depending on the tool. You can also pipe into grep or jq to process JSON:
aws list | grep RUNNING
What is the fastest way to debug a AWS CLI error?
Add the verbose flag (--verbose, -v or --debug) to the failing command. This reveals the underlying HTTP/API calls and the full error response body.
Official sources & references
Commands cross-checked against vendor documentation and high-authority repositories: