Software · head to head
Fluentd vs CloudWatch
The short version
- Each has a real cost: Fluentd fluentd needs more than 60 MB of memory at runtime, against roughly 450 KB for Fluent Bit; CloudWatch the free tier covers 5 GB of log ingestion and 10 custom metrics a month, after which log ingestion is $0.50 per GB from 5 to 30 GB
- They diverge on capability: Fluentd covers Log collection, CloudWatch covers Metrics collection.
Where they differ
Only the attributes on which Fluentd and CloudWatch actually diverge.
| Attribute | Fluentd | CloudWatch |
|---|---|---|
| Pricing model | open-source | usage-based |
| Founded | 2011 | 2006 |
Identical on both: starting price (Free), free tier (Yes), platforms (Web, Api), user rating (Not yet rated), category (Unknown).
What each one covers
Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.
Only in Fluentd
- Log collection
- Data parsing
- Filtering and buffering
- Event routing
Only in CloudWatch
- Metrics collection
- Log aggregation
- Dashboards
- Alarms and notifications
Both cover
- API
- Webhooks
- REST
- Web support
- Api support
What people use each for
The jobs each tool is most often brought in to do.
Fluentd
- Unified log collection and routing from many sources to many destinationsnot CloudWatch
- Parsing and transforming log records before forwardingnot CloudWatch
- Aggregating logs from containers into Elasticsearch, S3 or a SIEMnot CloudWatch
CloudWatch
- Metrics and log collection for AWS workloadsnot Fluentd
- Alarming on thresholds across AWS servicesnot Fluentd
- Querying logs with Logs Insightsnot Fluentd
- Live tailing logs during an incidentnot Fluentd
- Distributed tracing alongside X-Raynot Fluentd
Where each one falls short
Documented limitations, not opinions. Every one is a constraint you would hit in normal use.
Fluentd
- Fluentd needs more than 60 MB of memory at runtime, against roughly 450 KB for Fluent Bit
- Fluentd is built as a Ruby gem and depends on other gems, so a Ruby runtime is required
- Its capability comes from over 1,000 external plugins rather than built in functionality, so each added input or output is a separate dependency
- The Fluent Bit documentation states that cloud providers have switched from Fluentd to Fluent Bit for performance and compatibility and calls Fluent Bit the next generation solution
CloudWatch
- The free tier covers 5 GB of log ingestion and 10 custom metrics a month, after which log ingestion is $0.50 per GB from 5 to 30 GB
- Custom metrics are $0.30 each for the first 10,000, so instrumenting broadly gets expensive before volume discounts apply
- Each custom dashboard beyond the free three is $3 a month
- Alarms are billed at $0.10 per alarm metric a month, with high-resolution alarms costing more
- Log storage beyond the free 5 GB is $0.03 per GB per month on top of the ingestion charge
Pricing, plan by plan
Fluentd
Free- FreeFree
- Log collection
- Data parsing
- Filtering and buffering
CloudWatch
Free- FreeFree
- Metrics collection
- Log aggregation
- Dashboards
Which should you pick?
Choose Fluentd if
- You need log collection.
- You want to start without paying.
- You work on Web, Api.
- You also want data parsing.
Choose CloudWatch if
- You need metrics collection.
- You want to start without paying.
- You work on Web, Api.
- You also want log aggregation.
Questions people ask
- Is Fluentd or CloudWatch better?
- Neither clearly leads. Fluentd starts at Free and CloudWatch at Free, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
- Which is cheaper, Fluentd or CloudWatch?
- Fluentd starts at Free and CloudWatch at Free.
- Does Fluentd or CloudWatch run on more platforms?
- Both run on Web, Api, so platform support will not decide this one for you.
- Can I use Fluentd for free?
- Both have a free tier, so you can try either at no cost before committing.
- What is Fluentd best used for?
- Fluentd is most often used for unified log collection and routing from many sources to many destinations, parsing and transforming log records before forwarding, aggregating logs from containers into elasticsearch, s3 or a siem. Of those, unified log collection and routing from many sources to many destinations and parsing and transforming log records before forwarding are not what CloudWatch is typically brought in for.
- What can Fluentd do that CloudWatch cannot?
- Fluentd covers Log collection, Data parsing, Filtering and buffering, Event routing. CloudWatch covers Metrics collection, Log aggregation, Dashboards, Alarms and notifications. Both handle API, Webhooks, REST, Web support.


