Amazon S3 Streams
A Stream under an Amazon S3 Source watches one bucket and, optionally, a key prefix. There's no file path - you point at where the log objects land, and LogRaker polls for new ones.
Bucket
The S3 bucket to watch, e.g. my-logs-bucket. Required. Click 'Choose' to pick from the buckets in the account instead of typing the name. If the credentials aren’t permitted to list buckets, the picker says so and you can type the name; streaming itself doesn’t need that permission.
Prefix (optional)
A key prefix that scopes the listing to just the objects you care about, e.g. AWSLogs/123456789012/elasticloadbalancing/us-east-1/. Leave it blank to watch the whole bucket. For a bucket with a lot of objects, a prefix is strongly recommended - it keeps each poll cheap and focused. (A listing is bounded: if it would run past ten pages, LogRaker stops and shows a note asking you to narrow the prefix, rather than paging forever.)
Click 'Browse…' rather than typing it. The browser walks the bucket in columns, the way Finder does - pick a folder on the left and its contents appear to the right - and fills the field in for you. A footer shows how many objects and folders sit under the selection, and how long ago the newest one arrived, so you can tell a busy prefix from an empty one before you save. Turn on 'Show Preview' below the columns to see the last lines of the newest object under the selection, read the way the Stream reads them.
'Jump to Newest' skips the drilling and goes straight to the folder holding the most recent objects.
Logs are usually delivered into dated folders, so a prefix naming one particular day stops receiving anything once that day is over. When you pick a dated folder, 'Follow New Dates' appears beside 'Jump to Newest', turned on: 'Choose' then saves the folder that contains the dated ones, and the line under the browser names it. Turn it off to save exactly the folder you picked.
Some credentials are allowed to read one prefix but not to list the bucket as a whole. The browser then starts as deep as it's permitted, and says so. If it can't find anywhere to start, type a prefix you do have access to in the Prefix field and click 'Browse…' again.
Poll every (optional)
How often LogRaker lists the bucket for new objects, in seconds. Leave it blank for the default (30 seconds). Listing is inexpensive, so there's little reason to change it - but a very chatty prefix can poll faster, and a quiet one slower.
Format
Delivered objects are read as generic log text - one record per line, with gzip decompressed automatically when detected. This handles ALB / ELB and CloudFront access logs, Firehose output, and plain-text or NDJSON logs.
CloudTrail is read specially, because a CloudTrail object is a single JSON document holding hundreds of events - shown raw it would be one line several kilobytes wide. LogRaker splits it into one line per event, each led by the event time so it sorts on the timeline alongside your other Streams:
2026-08-27T22:36:35Z ListManagedNotificationEvents notifications.amazonaws.com user=Root:root src=140.248.1.235 region=us-east-1
Failed calls carry their error= code and message on the same line. CloudTrail objects are recognised by their key, so nothing needs configuring. Parsers that break the remaining formats into named fields are planned for a later release.
Filter (display)
The pill filter is the same client-side display filter every Stream kind has: it hides non-matching lines in the pane without changing what's fetched. Strip matched text from output redacts the matched substring from the lines it keeps.
Auto-stream at startup
When on, the Stream starts watching automatically when LogRaker launches. When off, it comes online the first time you select it in the sidebar.
What an S3 Stream costs
Amazon charges for S3 requests and for data transferred out of AWS, so a running Stream has a small cost, unlike local files and SSH Sources. While a Stream runs, it lists its prefix once per poll - every 30 seconds unless you change Poll every, with a few more requests when many new objects arrived at once - and downloads each new log object in full. When it connects, it also downloads the most recent objects under the prefix to fill the pane.
Listing costs very little. Downloads are what add up: a busy prefix delivering large logs, such as CloudTrail or load balancer logs, transfers that much data out of AWS for as long as the Stream runs, whether or not you are looking at the pane. A Stream set to auto-stream starts every time LogRaker launches. The Amazon S3 pricing page has the current rates.
Seeding on connect
When a Stream first connects, LogRaker seeds the pane with the most recent objects under the prefix so it isn't empty, then polls forward from there - showing each new object as it's delivered. It remembers where it left off, so a brief network blip resumes forward without re-showing lines or skipping any. Because delivery to S3 is batched, new objects appear a few minutes behind live (typically 1-5), set by the log producer.
Looking at an earlier date
When a Stream's logs are filed in dated folders, a bar with a calendar sits above its lines, showing the date the newest lines come from as Year, Month and Day, and Hour where the logs are filed by hour. That includes dates the Stream's prefix already names. Pick another value from any of them: the pane then shows that date's lines in place of the live tail, starting from the newest date inside what you picked. The bar names the date showing and how many objects it read, and 'Back to Live' returns to the tail.
Looking back changes only that pane. The Stream keeps tailing, and Monitors, other panes and widgets carry on with its live lines. A date holding more than 500 objects shows its first 500, and the bar says so.
Test
Click Test to list a recent object under the bucket and prefix with the Source's credentials. It confirms the bucket is reachable and that this identity can read it, and tells you whether any objects are present yet.