Log Processor¶
Centralized AWS log processing that deploys in minutes. Ingest, search, and analyze your CloudWatch logs with Athena, OpenSearch, and pre-built dashboards — the solution runs entirely in your AWS account, so no data leaves your VPC.
What it is¶
Log Processor is a self-contained log pipeline you deploy into your own AWS account via a single CloudFormation stack. It ingests CloudWatch log groups through Kinesis Firehose, stores them in S3, and indexes them into OpenSearch and Athena for search and analytics. It ships with pattern detection, ingest pipelines, retention policies, compliance reporting, a browser-based subscription editor, and a monitoring dashboard — all production-ready out of the box.
Who it's for¶
Teams that want centralized AWS logging without the weeks of manual setup, the unpredictable per-GB ingestion fees of third-party SaaS, or the data egress of sending logs outside their account. It's a fit for organizations subject to SOC 2, HIPAA, PCI-DSS, or FedRAMP requirements, since everything runs inside isolated VPC subnets with encryption at rest and no internet egress.
The one-line value¶
One CloudFormation deploy gives you an OpenSearch + Athena log pipeline that runs entirely in your VPC, billed as a flat software fee with no vendor markup on log volume — you pay AWS at cost.
What you get¶
- Automated CloudWatch ingestion via Firehose to an S3 datalake, cross-account capable
- OpenSearch full-text search with pre-built dashboards and ISM retention policies
- Athena SQL queries over partition-projected Glue tables — no crawlers needed
- 50+ built-in pattern detectors (redact / filter / tag) at no extra cost
- 14 built-in ingest pipelines that extract structured fields at index time
- Independent retention policies at every layer of the pipeline
- Automated compliance reports with system-health indicators
- A pre-built CloudWatch monitoring dashboard and alarms
- Role-based access control and SSO (SAML / OIDC) on higher tiers
- Cross-account log and S3 access-log ingestion on the Enterprise tier
How it works¶
- Subscribe — Find Log Processor on AWS Marketplace and subscribe.
- Launch — Deploy the CloudFormation stack, selecting your tier, domain, and certificate ARN.
- Configure — Configure your log subscriptions and start querying.
Essential tier and above include OpenSearch; the domain initializes automatically during deployment (roughly 15–25 minutes).

Works with the Perfware suite¶
Log Processor is a standalone product, but pattern detections can be flagged for cross-log correlation analysis by the companion AI Monitor product. See Pattern Detection for the AI Monitor correlation flag.