Build CloudWatch metric filter configurations with filter patterns, metric transformations, and custom dimensions.
Output will appear here...Build a CloudWatch Logs metric filter that turns matching log lines into a custom metric via one or more MetricTransformation entries, each mapping a filter-pattern match to a namespace, metric name, value, and a DefaultValue that's emitted when a given time period has zero matching log events. That DefaultValue field is easy to overlook but consequential: without it, a period with zero matching error lines simply has no data point at all for the metric (not a zero), which matters directly for a CloudWatch alarm evaluating 'missing data' behavior differently from an actual zero value, a common cause of an error-rate alarm that never fires because the metric has gaps instead of real zeros during healthy periods.
Always set DefaultValue explicitly (usually 0) on any metric transformation that feeds an alarm, an unset default creates data gaps during healthy periods that can silently break alarm evaluation logic depending on the alarm's missing-data treatment setting.
A metric filter only sees log data from its creation point forward, don't expect it to retroactively populate a historical trend, if you need historical error-rate analysis, that has to come from a Logs Insights query against the raw log data instead.
Test a new filter pattern against a sample of real log lines before relying on it, a pattern that's subtly wrong (a typo in a JSON path, or overly broad plain-text matching) either silently matches nothing or matches too much, and neither failure mode produces an obvious error, just a misleading metric.
The tool validates filterName, logGroupName, filterPattern, and each transformation's required fields locally, then constructs the equivalent PutMetricFilter request body, the same information CloudWatch Logs needs to know which log group to watch, what pattern to match, and how matched events map to metric data points; it can't verify the log group actually exists or that the filter pattern syntax matches real log line structure, that's only confirmed once the filter is applied against live logs.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.