Getting Started¶
Log Processor deploys as a single CloudFormation stack into your own AWS account. The flow is: subscribe on AWS Marketplace, launch the stack, then configure your log subscriptions. A typical deployment is production-ready in about 30 minutes.
Prerequisites¶
- An AWS account and a user with sufficient permissions to deploy the stack.
- Basic familiarity with the AWS Console (CloudFormation, S3, CloudWatch) and the ability to run AWS CLI commands from a terminal. No programming or infrastructure-as-code experience is required — the stack deploys via a single CloudFormation template with guided parameters.
- A custom domain and an ACM certificate for HTTPS access to Dashboards.
- Use the
check-quotascript to confirm you have sufficient AWS resources before deploying — for example current VPC utilization and OpenSearch instance-type support in your region. - Use the provided
.cmd/.shhelper scripts to manage the domain, users, stack deletion, cross-account setup, and snapshot operations.
Deploy time¶
- Overall deployment is typically ready in about 30 minutes.
- On Essential tier and above, the OpenSearch domain initializes automatically during deployment, which takes roughly 15–25 minutes.
Step 1: Subscribe and launch the main stack¶
- Find Log Processor on the AWS Marketplace console and select your tier.
- Click Continue to Subscribe and accept the terms.
- After a minute, click Set up your account.
- On the Fulfillment page, click deploy for the tier you purchased.
- CloudFormation opens with the template pre-loaded.
Step 2: Configure the main stack¶
CloudFormation opens with the template pre-loaded. Fill in the parameters below; you can typically leave the others at their defaults.
| Parameter | Required | Description |
|---|---|---|
ConfirmStackName |
Yes | Copy and paste your stack name here to confirm it meets the stack-name criteria. |
NotifyEmail |
Yes | Comma-separated list of email addresses (up to 5) for CloudWatch alarm notifications and compliance reports. You will receive an "AWS Notification - Subscription Confirmation" email. |
CrossAccountIds |
No | Comma-separated AWS account IDs allowed to send logs and replicate S3 access logs to this stack (e.g. 111111111111,222222222222). Leave empty for single-account. |
OrganizationId |
No | AWS Organization ID (e.g. o-abc123xyz). If set, any account in the organization can deliver logs without listing individual account IDs. |
DashboardsAllowedCidr |
Yes | Comma-separated IP ranges allowed to access Dashboards (up to 5), or 0.0.0.0/0 for open access. |
DashboardsCertificateArn |
Yes | ARN of an ACM certificate for HTTPS. |
DashboardsDomain |
Yes | Custom domain for Dashboards (e.g. dashboards.example.com). Provides a stable URL that persists across stack updates. Without it you must use the ALB-generated DNS name, which changes if the stack is recreated. |
Step 3: Configure subscriptions and query¶
Once the stack is healthy, configure your log subscriptions:
- On Essential tier and above, use the browser-based Subscription Editor to add log groups, configure stream routing, set retention, and define pattern rules.
- On Basic tier, update the subscriptions JSON file directly in the assets S3 bucket.
Changes are picked up automatically — no redeployment needed. Then search in OpenSearch or query the datalake with Athena.
Running multiple instances¶
You can host multiple instances side by side by selecting a tier and providing a unique stack name for each. Every stack deploys into its own VPC with isolated resources, which is useful for separate environments (dev vs prod) or different teams. Standard AWS limits apply.
Infrastructure costs¶
Log Processor is a SaaS application that provisions and operates resources directly within your own AWS account. All AWS infrastructure, compute, storage, and data-transfer fees incurred by the deployment are billed directly to your AWS account by Amazon Web Services, separate from and in addition to the software subscription fee. See Pricing for details.