Resolved - Cloudwatch Logs Ingestion Interruption

Incident Report for cloud.gov

Resolved

Resolved: Cloudwatch logs (for example, RDS logs) did not ingest into Cloud.gov Logs between December 4, 2025 at 11:14 AM ET and December 17, 1:45 PM ET.

The issue was caused by a production change that required AES-256 encryption on the S3 buckets used for log ingestion. This change prevented a Lambda in the ingestion pipeline from successfully writing logs to S3. The Lambda did not surface errors, which delayed detection.

At 1:45 PM ET on December 17, the bucket policy was corrected and log ingestion was resumed. No further customer action is required.

Impact: Customers may see gaps in Cloudwatch log data for the affected time window.

Prevention: We are improving ingestion monitoring, expanding end-to-end smoke tests, and updating our error handling so failures surface immediately.

Next update: No further updates are planned.
Posted Dec 17, 2025 - 01:45 EST