Goa.Functions.CloudWatchLogs
0.9.2-preview
dotnet add package Goa.Functions.CloudWatchLogs --version 0.9.2-preview
NuGet\Install-Package Goa.Functions.CloudWatchLogs -Version 0.9.2-preview
<PackageReference Include="Goa.Functions.CloudWatchLogs" Version="0.9.2-preview" />
<PackageVersion Include="Goa.Functions.CloudWatchLogs" Version="0.9.2-preview" />
<PackageReference Include="Goa.Functions.CloudWatchLogs" />
paket add Goa.Functions.CloudWatchLogs --version 0.9.2-preview
#r "nuget: Goa.Functions.CloudWatchLogs, 0.9.2-preview"
#:package Goa.Functions.CloudWatchLogs@0.9.2-preview
#addin nuget:?package=Goa.Functions.CloudWatchLogs&version=0.9.2-preview&prerelease
#tool nuget:?package=Goa.Functions.CloudWatchLogs&version=0.9.2-preview&prerelease
Goa.Functions.CloudWatchLogs
Process CloudWatch Logs subscription filter events in AWS Lambda with high performance and native AOT support. This package provides automatic base64+gzip decompression, flexible batch or single-event handling, and seamless integration with CloudWatch Logs features like extracted fields and subscription filters for real-time log processing workflows.
Quick Start
dotnet new install Goa.Templates
dotnet new goa.cloudwatchlogs -n "MyCloudWatchLogsFunction"
Features
- Automatic Decompression: Base64 decode and gzip decompress handled automatically
- Flexible Processing Modes: Process log events individually or as a batch
- Control Message Filtering: Automatically skip connectivity check messages in single-event mode
- Extracted Fields: Access fields extracted by subscription filter patterns
- Native AOT Ready: Optimized for ahead-of-time compilation with minimal cold starts
- Dependency Injection: Full integration with .NET's dependency injection container
Basic Usage
Process Events One at a Time
using Goa.Functions.Core;
using Goa.Functions.CloudWatchLogs;
using Microsoft.Extensions.Hosting;
await Host.CreateDefaultBuilder()
.UseLambdaLifecycle()
.ForCloudWatchLogs()
.ProcessOneAtATime()
.HandleWith<ILoggerFactory>((loggerFactory, logEvent, context) =>
{
var logger = loggerFactory.CreateLogger("CloudWatchLogsHandler");
// Access log metadata from context
var logGroup = context.LogGroup;
var logStream = context.LogStream;
// Process the individual log event
logger.LogInformation("[{Timestamp}] {Message}", logEvent.TimestampDateTime, logEvent.Message);
// Access extracted fields if configured in subscription filter
if (logEvent.ExtractedFields?.TryGetValue("level", out var level) == true)
{
if (level == "ERROR")
{
// Handle error logs specially
}
}
return Task.CompletedTask;
})
.RunAsync();
Process Events as a Batch
await Host.CreateDefaultBuilder()
.UseLambdaLifecycle()
.ForCloudWatchLogs()
.ProcessAsBatch()
.HandleWith<ILoggerFactory>((loggerFactory, logsEvent) =>
{
var logger = loggerFactory.CreateLogger("CloudWatchLogsHandler");
// Check for control messages (connectivity checks from CloudWatch)
if (logsEvent.IsControlMessage)
{
logger.LogDebug("Received control message, skipping processing");
return Task.CompletedTask;
}
logger.LogInformation("Processing {Count} log events from {LogGroup}/{LogStream}",
logsEvent.LogEvents?.Count ?? 0, logsEvent.LogGroup, logsEvent.LogStream);
foreach (var logEvent in logsEvent.LogEvents ?? [])
{
// Process each log event
}
return Task.CompletedTask;
})
.RunAsync();
CloudWatch Logs Event Structure
When Lambda receives events from CloudWatch Logs subscription filters, the data arrives base64-encoded and gzip-compressed. This package handles decompression automatically.
CloudWatchLogsEvent Properties
| Property | Type | Description |
|---|---|---|
Owner |
string? |
AWS account ID that owns the log data |
LogGroup |
string? |
Log group name |
LogStream |
string? |
Log stream name |
SubscriptionFilters |
IList<string>? |
Subscription filter names that matched |
MessageType |
string? |
"DATA_MESSAGE" or "CONTROL_MESSAGE" |
PolicyLevel |
string? |
Policy level (e.g., "ACCOUNT_LEVEL") |
LogEvents |
IList<CloudWatchLogEvent>? |
The log events |
IsControlMessage |
bool |
True if this is a connectivity check |
IsDataMessage |
bool |
True if this contains actual log data |
CloudWatchLogEvent Properties
| Property | Type | Description |
|---|---|---|
Id |
string? |
Unique identifier for this log event |
Timestamp |
long |
Unix timestamp in milliseconds |
Message |
string? |
The log message content |
ExtractedFields |
Dictionary<string, string>? |
Fields extracted by filter pattern |
TimestampDateTime |
DateTimeOffset |
Timestamp as DateTimeOffset |
Documentation
For more information and examples, visit the main Goa documentation.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Goa.Functions.Core (>= 0.9.2-preview)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.9.2-preview | 37 | 9/29/2026 |
| 0.9.1-preview | 173 | 8/24/2026 |
| 0.9.0-preview | 469 | 6/18/2026 |
| 0.8.0-preview | 411 | 3/17/2026 |
| 0.7.8-preview | 115 | 3/3/2026 |
| 0.7.7-preview | 86 | 3/3/2026 |
| 0.7.6-preview | 71 | 3/3/2026 |
| 0.7.5-preview | 92 | 3/2/2026 |
| 0.7.4-preview | 88 | 3/1/2026 |
| 0.7.3-preview | 83 | 2/28/2026 |
| 0.7.2-preview | 110 | 2/23/2026 |
| 0.7.1-preview | 129 | 1/26/2026 |
| 0.7.0-preview | 84 | 1/26/2026 |
| 0.2.1-preview | 98 | 1/20/2026 |
| 0.2.0-preview | 94 | 1/14/2026 |
| 0.1.9-preview | 104 | 1/1/2026 |
| 0.1.8-preview | 281 | 12/15/2025 |
| 0.1.7-preview | 229 | 12/15/2025 |
| 0.1.6-preview | 228 | 12/15/2025 |
| 0.1.5-preview | 242 | 12/15/2025 |