Blenra LogoBlenra
Optimized for: Gemini / ChatGPT / Claude
#Security

Advanced AI Prompt for AWS IAM Policy for CloudWatch Logs with Log Group Restriction

Customize the variables below to instantly engineer your prompt.

Required Variables

advanced-ai-prompt-cloudwatch-logs-least-privilege.txt
Act as a Cloud Observability Security Engineer. Generate a strict JSON IAM policy for an application executing in AWS that requires authorization to emit telemetry to CloudWatch Logs. Restrict the `logs:CreateLogStream` and `logs:PutLogEvents` actions exclusively to the specific log group ARN: `arn:aws:logs:[REGION]:[ACCOUNT_ID]:log-group:[LOG_GROUP_NAME]:*`. Explicitly omit the `logs:CreateLogGroup` permission to prevent the application from arbitrarily creating new log groups, and omit all deletion permissions. This guarantees the application cannot interfere with, overwrite, or pollute the logging streams of other microservices operating in the same account.

Example Text Output

"The AI produces a precise policy limiting the 'Resource' field to the specific log group ARN, preventing global CloudWatch access."

More Cloud & DevOps Prompts

View all →

Frequently Asked Questions

What is the "Advanced AI Prompt for AWS IAM Policy for CloudWatch Logs with Log Group Restriction" prompt used for?

The AI produces a precise policy limiting the 'Resource' field to the specific log group ARN, preventing global CloudWatch access.

Which AI tools work with this prompt?

This prompt is optimized for Gemini / ChatGPT / Claude, but works great with ChatGPT, Claude, Gemini, and other large language models. Simply copy it and paste it into your preferred AI tool.

How do I customize this prompt?

Use the variable fields above to fill in your specific details. The prompt will auto-update as you type, ready to copy instantly.

Is this prompt free?

Yes! All prompts on Blenra are free to copy and use immediately. No account required.