Skip to main content

Introduction

Log drains forward your application logs to an external destination in near real time. Draining logs allows you to store your logs indefinitely to meet your own retention needs, archive them for compliance, or feed them into your preferred search and observability tooling.
Log drains are available for Enterprise plan customers.
They may be added to an environment at any time via the Environment → Settings → Log Drains page, and you can run as up to 5 drains per environment.

Supported destinations

Laravel Cloud currently supports draining to Amazon S3, with additional destinations planned.

Amazon S3

Stream logs to an S3 bucket you own. Laravel Cloud authenticates with AWS by assuming an IAM role in your account. Configure the drain with the following properties:
Create an IAM role that trusts Laravel Cloud and grants write access to the specified S3 bucket, then paste the role ARN into the drain configuration. See AWS IAM setup below, or use View AWS IAM setup when creating or editing a drain on the Environment → Settings → Log Drains page for environment-specific policies.

Path structure

Laravel Cloud writes each log file to a time-partitioned path within your bucket, so logs are organized by environment, delivery time, and stream. By default, files are written from the root of the bucket under the environment’s identifier:
If you set a path prefix, it replaces the environment identifier. For example, a drain with the path prefix invoice-app would write:

AWS IAM setup

Create an IAM role in your AWS account with the “Custom trust policy” entity type. Attach the trust and permissions policies below, then paste the role ARN into Laravel Cloud. We recommend a dedicated role for each drain. You may reuse the same role across multiple applications and environments if you prefer to manage a single role.

Role trust policy

The trust policy allows Laravel Cloud to assume the role. It must include Laravel Cloud’s writer role as the principal and your organization’s external ID as a condition.
Use View AWS IAM setup in the log drain configuration page for the exact external ID for your organization.

Permissions policy

The permissions policy grants the access a drain needs to write objects to your bucket:
Use View AWS IAM setup on the log drain configuration page to copy a policy with your bucket, path prefix, and environment identifier already filled in. If you reuse a single role across multiple applications and environments, paste the same role ARN into each drain. If those drains share a bucket, replace the PutObject resource so it covers every prefix they write to. You may grant write access to the entire bucket:
Or list only the prefixes you want the role to write to:
If a drain does not set a path prefix, use the environment identifier from that drain’s IAM setup policy in the resource list. If those drains write to different buckets, include each bucket in both the ListBucket and PutObject resources:

Pricing

Log drains are billed for the time each drain runs and the volume of data it processes. For rates and a worked billing example, see Log Drains Pricing.