How to see a Lambda function's logs and recent errors
Updated · 4 min read
A function is failing and you want the error message. Lambda doesn't keep logs itself: everything a function prints goes to CloudWatch Logs, into a log group called /aws/lambda/<function name> in the function's own region. Inside the group, each running copy of the function writes its own "log stream", so a busy function has thousands of them, and the error you want is in one.
In the AWS console
- Open the function in Lambda (in its region), go to the Monitor tab and click View CloudWatch logs. That opens the log group, with its streams listed newest first.
- Rather than opening streams one by one, click Search log group and type
ERROR, or"Task timed out"for timeouts. That searches every stream at once. - For anything more involved, open Logs Insights from the CloudWatch menu, pick the log group, and run a query like this one:
fields @timestamp, @message
| filter @message like /(?i)(exception|error|fail|timed out)/
| sort @timestamp desc
| limit 50The Monitor tab's Errors graph is often the quickest answer to "how many, and since when?". Read the logs once you know where to look.
With the AWS CLI
The last hour, one line per message:
aws logs tail /aws/lambda/my-function --since 1h --format short --region us-east-2Add --follow to keep watching as new lines arrive, which is handy while you test.
Only the errors from the last day:
aws logs tail /aws/lambda/my-function --since 1d --format short \
--filter-pattern '?ERROR ?Error ?"Task timed out"'A ? in front of each term means "any of these". Filter patterns are case-sensitive, which is why both ERROR and Error are there.
How many errors there were, hour by hour, without reading any logs:
aws cloudwatch get-metric-statistics --region us-east-2 \
--namespace AWS/Lambda --metric-name Errors \
--dimensions Name=FunctionName,Value=my-function \
--start-time 2026-10-02T00:00:00Z --end-time 2026-10-03T00:00:00Z \
--period 3600 --statistics SumThe same Logs Insights query from the terminal, over the last 24 hours:
aws logs start-query --log-group-name /aws/lambda/my-function \
--start-time $(( $(date +%s) - 86400 )) --end-time $(date +%s) \
--query-string 'fields @timestamp, @message | filter @message like /(?i)(exception|error|fail|timed out)/ | sort @timestamp desc | limit 50'
# then, with the queryId it prints:
aws logs get-query-results --query-id 12ab3456-12ab-123a-789e-1234567890abLogs Insights is billed by how much log data it scans, so keep the time range short on busy functions.
When there are no logs
- The log group might be somewhere else. Functions can be set to log to a different group. Check with
aws lambda get-function-configuration --function-name my-function --query LoggingConfig.LogGroup --output text. - The function's role can't write logs. It needs
logs:CreateLogGroup,logs:CreateLogStreamandlogs:PutLogEvents. AWS'sAWSLambdaBasicExecutionRolepolicy has all three. - It never ran. No invocations, no log group. The Monitor tab's Invocations graph will be flat.
While you're there: log groups keep everything forever unless you set a retention period, and that storage shows up on the bill. aws logs put-retention-policy --log-group-name /aws/lambda/my-function --retention-in-days 30 keeps a month. More in how to find out what's costing money in AWS.
Or in Cloud GUI
Cloud GUI's Functions page lists every function from every region with its calls and errors for the last 24 hours, so you can see which one is failing, and since when, without opening anything. Open a function and its page has an hourly chart of the same, then Recent logs: the newest lines from the last hour (up to 200), newest first, with times in UTC. Errors only keeps the lines containing ERROR, Error, Exception, FATAL, Traceback, Task timed out or Process exited before completing, and error lines are marked with an Error label so they stand out. It reads the function's own log group, including a custom one if the function is set to use it.
The Logs page lists every CloudWatch log group in every region, with how much each stores and how long it keeps lines. Open one to see its newest lines, or search it for exact text (case-sensitive, as CloudWatch searches) over the last hour or the last 24 hours.
Reading log lines needs version 3 of Cloud GUI's read-only role, with its AllowLogs setting left at true. Accounts connected before version 3 see a banner that opens the stack update in AWS. The lines pass through Cloud GUI on their way to your screen and are never stored. How access works.