We also had EC2 instances with access logs / error logs from Apache, some services would get data into AWS CloudWatch or Slack. Lastly, we also had some usage of AWS Elastichsearch.
Over the course of 4 years we tried to move as much as we could to this exact same setup.
We got pretty far with this and it started helping immensely not having to dig through multiple places to dig up what happened in the lifecycle of issues that we were debugging.
I’ve been pretty successful with this project and as of today, nearly 45% of all our reporting features run on top of this service.