A Lambda function returns correct results, but no log group appears for it in CloudWatch Logs, so the team cannot see any of its output. The function was deployed with a minimal execution role that a developer wrote by hand.
What is the cause?
- A.
The function's reserved concurrency is set to zero, which suppresses log delivery to CloudWatch Logs while still allowing the function itself to run normally.
- B.
CloudWatch Logs creates a log group for a function only after it has been invoked at least one hundred times, and this function has not reached that count.
- C.
Lambda writes output to CloudWatch Logs only when the function's logging configuration sets the system log level to DEBUG rather than the default INFO level.
- D.
The execution role does not grant logs:CreateLogGroup, logs:CreateLogStream and logs:PutLogEvents.
Show answer
Answer: D
Lambda writes logs using the function's execution role, so a role without CloudWatch Logs permissions produces no log group at all.
- A. Reserved concurrency of zero would stop the function from running entirely; it does not selectively disable logging.
- B. Lambda creates the log group on the first invocation that has permission to create it; there is no invocation-count threshold.
- C. Log level controls which platform events are emitted, not whether the function's own output reaches CloudWatch Logs at all.
- D. Correct. The runtime writes logs with the execution role's credentials, so missing logs permissions means no log group is ever created.
