Sumo’s LogGroup Lambda Connector automates the process of creating Amazon Cloudwatch Log Group subscriptions.
You can use the connector with Sumo Lambda functions, available at https://github.com/SumoLogic/sumologic-aws-lambda, or with other Lambda functions of your own.
This page has instructions for configuring and deploying the LogGroup Lambda Connector using a CloudFormation template.
Step 1. Download the CloudFormation template
You can use a Sumo-provided CloudFormation template,
loggroup-lambda-cft.json,to automate the deployment of the LogGroup Lambda Connector. The template creates the following resources:
PermissionForEventsToInvokeLambda—Permission to CloudTrail events for invoking the Lambda function (SumoLogGroupLambdaConnector).
SumoLGCnCreateLogGroupTrigger—A CloudTrail Event Rule which triggers the Lambda function (SumoLogGroupLambdaConnector) on the CreateLogGroup event.
SumoLGCnLambdaExecutionRole—An IAM Role for the Lambda function which defines permissions to create subscription filters and CloudWatch logs.
SumoLogGroupLambdaConnector—The Lambda function responsible for creating a subscription filter on Log Groups that match specified filter criteria.
Step 2. Define environment variables
In this step you define environment variables that specify the destination Lambda function and the Log Groups you want to subscribe to it. You define the variables in the
loggroup-lambda-cft.json file that you downloaded in the previous step.
- Locate the “Environment” section of
LAMBDA_ARNenvironment variable defines the Amazon Resource Name (ARN) of the Lambda function. Edit the function attribute In the
TestLambdawith the desired function name.
Save the file.
Step 3: Create a stack
In this step, you create a stack using the AWS CloudFormation console.
Log in to the AWS Management Console.
Under Management Tool, select CloudFormation.
Create a new stack by clicking Create Stack.
In Select Template window, choose Upload a template to Amazon S3 and upload
Specify a stack name and click Next.
In Options window click Next again.
In Review window click the checkbox acknowledging that you understand this template creates IAM resources and click Create.
- After few seconds CREATE_COMPLETE should appear in the Status column.
Step 4: Test the Lambda function
To test the Lambda function
- Create a Log Group with a name that matches the regex you specified for
- After a few seconds, the Log Group should be subscribed to the Lambda function whose ARN you specified in the