> ## Documentation Index
> Fetch the complete documentation index at: https://docs.operata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Install Contact Flow Logs collection

> Deploy the CloudFormation stack that streams Amazon Connect Contact Flow Logs from CloudWatch into Operata.

Deploy the CloudFormation stack so Amazon Connect contact-flow logs stream from
CloudWatch into Operata — a test contact through a logged flow appears against
its Contact Trace Record (CTR) in the Operata console within five minutes of
contact end.

## Before you start

* An [Amazon Connect integration](/docs/integrations-amazon-connect-overview)
  already streaming Contact Trace Records to Operata.
* An [Operata account](/docs/get-started-overview) with Admin role and
  your Operata Group ID.
* AWS [IAM permissions](/docs/iam-policies) to deploy CloudFormation in
  the region hosting your Amazon Connect instance.
* [Contact Flow Logging enabled](https://docs.aws.amazon.com/connect/latest/adminguide/contact-flow-logs.html)
  on each contact flow you want to monitor. Enable it in the Amazon
  Connect console under each flow's settings, or by adding a **Set
  logging behavior** block to the flow.
* The CloudWatch log group name where Amazon Connect delivers your
  contact-flow logs.

## Steps

### 1. Send Operata the install details

Contact [Operata Support](mailto:support@operata.com) with:

* **AWS region** hosting your Amazon Connect instance.
* **CloudWatch log group name** — for example, `/aws/connect/operata-prod`.
* **Operata Group ID** — Operata can confirm yours if you do not have
  it on hand.
* **Amazon Connect instance alias** — 32 characters or fewer (for
  example, `operata-prod`).

Operata returns a quick-create CloudFormation link pre-filled with
your configuration.

### 2. Open the quick-create link

Click the link to open the [CloudFormation
console](https://console.aws.amazon.com/cloudformation). Every
parameter is pre-populated except the API key.

### 3. Enter your Operata API token

Paste an Operata API token into the **API key** parameter. Create one
in the Operata console under **Settings → Config → API**. See the
[Operata help article](https://help.operata.com/en/articles/5542797-how-do-i-create-view-change-and-revoke-api-tokens)
for the full lifecycle.

### 4. Deploy the stack

Acknowledge the IAM resource creation and click **Create stack**. The stack
reaches `CREATE_COMPLETE` in around five minutes. CloudFormation
provisions:

| Resource                                                                                             | Quantity | Purpose                                                            |
| ---------------------------------------------------------------------------------------------------- | -------- | ------------------------------------------------------------------ |
| [EventBridge Pipe](https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-pipes.html)           | 1        | Streams log events from CloudWatch to the Operata API destination. |
| [API Destination](https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-api-destinations.html) | 1        | The Operata API endpoint.                                          |
| [IAM Role](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html)                           | 1        | Service-execution role for the Pipe.                               |
| [IAM Policies](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html)                | 2        | CloudWatch source access and API destination invocation.           |
| [Secrets Manager Secret](https://docs.aws.amazon.com/secretsmanager/)                                | 1        | The Operata API key.                                               |

### 5. (Optional) Tag the new resources

Apply your cost-allocation and ownership tags. See [Tag your AWS
resources](/docs/aws-tagging).

### 6. Place a test contact

Trigger a call through a contact flow that has logging enabled. End
the contact cleanly.

## Verify

In the [Operata console](https://app.operata.io), open **Calls and
Logs → Summary** and locate the test contact. The contact-flow log
data appears within five minutes of contact end and joins the Contact
Trace Record by `ContactId`.

If nothing appears after five minutes, see [Troubleshooting](/docs/aws-troubleshooting).

## Data collected

Each event carries the raw contact-flow log entry as Amazon Connect
emits it, including:

* Contact flow name and ID.
* Contact ID (the join key against the Contact Trace Record).
* Block type and identifier for each step.
* Block results, branches taken, and any errors.
* Timestamps per flow-execution step.
* External endpoint references — Lambda ARNs, Lex bot aliases, and
  similar.

For the full schema, see the
[AWS Contact Flow Logs reference](https://docs.aws.amazon.com/connect/latest/adminguide/about-contact-flow-logs.html).

## Privacy

Raw contact-flow logs can carry customer PII in flow parameters and
external-results payloads. The integration ships a redaction Lambda
that runs in your AWS account before any log leaves AWS. See:

* [Configure Contact Flow Log redaction](/docs/contact-flow-log-privacy) — the field-tier schema and the mandatory keep-list.
* [Concept: Privacy and redaction](/docs/concepts-privacy-and-redaction) — the model the redaction Lambda enforces.

Contact [Operata Support](mailto:support@operata.com) for help selecting
a redaction configuration.

## Charges

All AWS service charges from this stack appear on your AWS bill. Contact
Flow Logs collection is included in every Operata plan at no additional
Operata cost. Primary cost factors:

* Amazon EventBridge Pipe event processing.
* CloudWatch Logs data transfer out of CloudWatch.
* Secrets Manager (rolled into the API destination charge).

You may incur additional [AWS data-transfer charges](https://aws.amazon.com/ec2/pricing/on-demand/#Data_Transfer)
for data leaving AWS to Operata.

## Deploying alongside other stacks

The Contact Flow Logs stack runs independently of the CTR, Contact
Lens, and Amazon Lex stacks. Add or remove any stack without affecting
the others.

## Related

* [Configure Contact Flow Log redaction](/docs/contact-flow-log-privacy) — strip PII fields before logs leave AWS.
* [Install the Amazon Lex integration](/docs/lex-integration) — pair flow logs with Lex bot intent and slot data.
* [Concept: Cloud Collector](/docs/concepts-cloud-collector) — the Operata-side runtime that joins flow logs to contacts.
* [Troubleshoot the AWS integration](/docs/aws-troubleshooting) — missing log events, IAM debugging, Amazon EventBridge Pipe failures.
