> ## Documentation Index
> Fetch the complete documentation index at: https://hoopdev-update-to-meta-tags.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS CloudWatch

> CloudWatch in Hoop simplifies AWS log analysis by providing direct access to log groups with automatic environment variable setup and an optimized interface for log exploration.

## Prerequisites

To get the most out of this guide, you will need to:

* Either [create an account in our managed instance](https://use.hoop.dev) or [deploy your own hoop.dev instance](/getting-started/installation/overview)
* You must be your account administrator to perform the following commands

## Features

The table below outlines the features available for this type of connection.

* **Native** - This refers to when a database client connects through a specific protocol, such as an IDE or client libraries through `hoop connect <connection-name>`.
* **One Off -** This term refers to accessing this connection from hoop web panel.

| Feature                        | Native                | One Off               | Description                                                                                                             |
| ------------------------------ | --------------------- | --------------------- | ----------------------------------------------------------------------------------------------------------------------- |
| TLS Termination Proxy          | <Icon icon="xmark" /> | <Icon icon="check" /> | The local proxy terminates the connection with TLS, enabling the connection with the remote server to be TLS encrypted. |
| Audit                          | <Icon icon="xmark" /> | <Icon icon="check" /> | The gateway stores and audits the queries being issued by the client                                                    |
| Data Masking (Google DLP)      | <Icon icon="xmark" /> | <Icon icon="check" /> | A policy can be enabled to mask sensitive fields dynamically when performing queries in the logs.                       |
| Data Masking (MS Presidio DLP) | <Icon icon="xmark" /> | <Icon icon="check" /> | A policy can be enabled to mask sensitive fields dynamically when performing queries in the logs.                       |
| Credentials Offload            | <Icon icon="xmark" /> | <Icon icon="check" /> | The user authenticates via SSO instead of using the service credentials.                                                |
| Interactive Access             | <Icon icon="xmark" /> | <Icon icon="check" /> | Interactive access is available when using an IDE or connecting via a terminal for log analysis exploration.            |

## Configuration

| Name                     | Type    | Required | Description                                                                                  |
| ------------------------ | ------- | -------- | -------------------------------------------------------------------------------------------- |
| AWS\_ACCESS\_KEY\_ID     | env-var | yes      | The AWS access key ID for CloudWatch Logs access                                             |
| AWS\_SECRET\_ACCESS\_KEY | env-var | yes      | The AWS secret access key for CloudWatch Logs access                                         |
| AWS\_REGION              | env-var | yes      | The AWS region where your CloudWatch log groups are located (e.g., `us-east-1`, `eu-west-1`) |

The AWS credentials require the minimal set of IAM permissions to work:

* `logs:DescribeLogGroups`
* `logs:FilterLogEvents`
* `logs:GetLogEvents`

## Connection Setup

The flag `--type custom/cloudwatch` allows displaying the introspection schema in the web interface.

```bash
hoop admin create conn my-cloudwatch -a <agent-name> \
    --type custom/cloudwatch \
    --overwrite \
    --schema=enabled \
    --skip-validation \
    -e AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE \
    -e AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY \
    -e AWS_REGION=us-west-2 \
    -- bash
```

<Warning>
  Currently, CloudWatch connections cannot be **created** through the web interface.
  Use the CLI command above to create the connection, then it will be available in the web app for use.
</Warning>

## Connection Usage

### CLI

```bash
hoop exec my-cloudwatch \
  -i 'aws logs filter-log-events --log-group-name /aws/lambda/my-function'
```

### Web panel

When you select a log group in the interface, the terminal will propagate the name as `LOG_GROUP_NAME` environment variable, allowing you to use it in your scripts.
The example above shows the variable being used in a script to filter events from the `/aws/lambda/my-function` log group.

<Frame>
  <img src="https://mintlify.s3.us-west-1.amazonaws.com/hoopdev-update-to-meta-tags/images/aws/client-aws-cloudwatch.png" alt="cloudwatch screenshot" />
</Frame>
