Introduction
Log drains forward your application logs to an external destination in near real time. Draining logs allows you to store your logs indefinitely to meet your own retention needs, archive them for compliance, or feed them into your preferred search and observability tooling.Log drains are available for Enterprise plan customers.
Supported destinations
Laravel Cloud currently supports draining to Amazon S3, with additional destinations planned.Amazon S3
Stream logs to an S3 bucket you own. Laravel Cloud authenticates with AWS by assuming an IAM role in your account. Configure the drain with the following properties:Create an IAM role that trusts Laravel Cloud and grants write access to the
specified S3 bucket, then paste the role ARN into the drain configuration. See
AWS IAM setup below, or use View AWS IAM setup when
creating or editing a drain on the Environment → Settings → Log Drains
page for environment-specific policies.
Path structure
Laravel Cloud writes each log file to a time-partitioned path within your bucket, so logs are organized by environment, delivery time, and stream. By default, files are written from the root of the bucket under the environment’s identifier:invoice-app would write:
AWS IAM setup
Create an IAM role in your AWS account with the “Custom trust policy” entity type. Attach the trust and permissions policies below, then paste the role ARN into Laravel Cloud. We recommend a dedicated role for each drain. You may reuse the same role across multiple applications and environments if you prefer to manage a single role.Role trust policy
The trust policy allows Laravel Cloud to assume the role. It must include Laravel Cloud’s writer role as the principal and your organization’s external ID as a condition.Permissions policy
The permissions policy grants the access a drain needs to write objects to your bucket:PutObject resource so it covers every prefix they write to. You may grant write access to the entire bucket:
ListBucket and PutObject resources:

