How to see a Lambda function's logs and recent errors

Updated · 4 min read

A function is failing and you want the error message. Lambda doesn't keep logs itself: everything a function prints goes to CloudWatch Logs, into a log group called /aws/lambda/<function name> in the function's own region. Inside the group, each running copy of the function writes its own "log stream", so a busy function has thousands of them, and the error you want is in one.

In the AWS console

  1. Open the function in Lambda (in its region), go to the Monitor tab and click View CloudWatch logs. That opens the log group, with its streams listed newest first.
  2. Rather than opening streams one by one, click Search log group and type ERROR, or "Task timed out" for timeouts. That searches every stream at once.
  3. For anything more involved, open Logs Insights from the CloudWatch menu, pick the log group, and run a query like this one:
fields @timestamp, @message
| filter @message like /(?i)(exception|error|fail|timed out)/
| sort @timestamp desc
| limit 50

The Monitor tab's Errors graph is often the quickest answer to "how many, and since when?". Read the logs once you know where to look.

With the AWS CLI

The last hour, one line per message:

aws logs tail /aws/lambda/my-function --since 1h --format short --region us-east-2

Add --follow to keep watching as new lines arrive, which is handy while you test.

Only the errors from the last day:

aws logs tail /aws/lambda/my-function --since 1d --format short \
  --filter-pattern '?ERROR ?Error ?"Task timed out"'

A ? in front of each term means "any of these". Filter patterns are case-sensitive, which is why both ERROR and Error are there.

How many errors there were, hour by hour, without reading any logs:

aws cloudwatch get-metric-statistics --region us-east-2 \
  --namespace AWS/Lambda --metric-name Errors \
  --dimensions Name=FunctionName,Value=my-function \
  --start-time 2026-10-02T00:00:00Z --end-time 2026-10-03T00:00:00Z \
  --period 3600 --statistics Sum

The same Logs Insights query from the terminal, over the last 24 hours:

aws logs start-query --log-group-name /aws/lambda/my-function \
  --start-time $(( $(date +%s) - 86400 )) --end-time $(date +%s) \
  --query-string 'fields @timestamp, @message | filter @message like /(?i)(exception|error|fail|timed out)/ | sort @timestamp desc | limit 50'

# then, with the queryId it prints:
aws logs get-query-results --query-id 12ab3456-12ab-123a-789e-1234567890ab

Logs Insights is billed by how much log data it scans, so keep the time range short on busy functions.

When there are no logs

  • The log group might be somewhere else. Functions can be set to log to a different group. Check with aws lambda get-function-configuration --function-name my-function --query LoggingConfig.LogGroup --output text.
  • The function's role can't write logs. It needs logs:CreateLogGroup, logs:CreateLogStream and logs:PutLogEvents. AWS's AWSLambdaBasicExecutionRole policy has all three.
  • It never ran. No invocations, no log group. The Monitor tab's Invocations graph will be flat.

While you're there: log groups keep everything forever unless you set a retention period, and that storage shows up on the bill. aws logs put-retention-policy --log-group-name /aws/lambda/my-function --retention-in-days 30 keeps a month. More in how to find out what's costing money in AWS.

Or in Cloud GUI

Cloud GUI's Functions page lists every function from every region with its calls and errors for the last 24 hours, so you can see which one is failing, and since when, without opening anything. Open a function and its page has an hourly chart of the same, then Recent logs: the newest lines from the last hour (up to 200), newest first, with times in UTC. Errors only keeps the lines containing ERROR, Error, Exception, FATAL, Traceback, Task timed out or Process exited before completing, and error lines are marked with an Error label so they stand out. It reads the function's own log group, including a custom one if the function is set to use it.

The Logs page lists every CloudWatch log group in every region, with how much each stores and how long it keeps lines. Open one to see its newest lines, or search it for exact text (case-sensitive, as CloudWatch searches) over the last hour or the last 24 hours.

Reading log lines needs version 3 of Cloud GUI's read-only role, with its AllowLogs setting left at true. Accounts connected before version 3 see a banner that opens the stack update in AWS. The lines pass through Cloud GUI on their way to your screen and are never stored. How access works.

See your whole AWS account in one calm view

Cloud GUI shows your files and functions from every region at once, in plain English, with what's failing up front. It connects with a read-only role you create and can delete any time. Free for one AWS account.

More guides

Free tool
IAM policy explainer

Paste an IAM policy and read it in plain English, with the risky parts flagged. It runs in your browser; nothing is sent anywhere.