About 5 years ago there was several places to check for information while debugging issues. We also had EC2 instances with access logs / error logs from Apache, some services would get data into AWS CloudWatch or Slack.
And in that account we have 1 SQS Queue which is worked by a Logstash container on a newer and limited account that holds AWS Elasticsearch and some other things.
For quite some time we have been going back and forth between only Elaticsearch and CloudWatch for debugging.
It already helped us diagnose some internal DoS issues as well as some Aurora / Elasticache DNS issues.