Part 4: Querying AWS Services with CloudWatch Logs
Navigating AWS Service Logs
AWS Lambda Logs
Lambda Log Structure
START RequestId: abc-123 Version: $LATEST
2024-01-15T10:30:45.123Z abc-123 INFO User logged in
END RequestId: abc-123
REPORT RequestId: abc-123 Duration: 125.45 ms Billed Duration: 126 ms Memory Size: 512 MB Max Memory Used: 95 MBFinding Errors in Lambda
fields @timestamp, @message
| filter @type = "REPORT" or @message like /ERROR|Error|error/
| filter @message not like /START|END/
| sort @timestamp desc
| limit 50Lambda Cold Start Analysis
Lambda Performance Metrics
Lambda Timeouts
Real Example: Lambda Error Tracking
API Gateway Logs
Enable API Gateway Logging
API Gateway Log Format
Query API Gateway Access Logs
API Gateway Error Rate
API Gateway Performance by Endpoint
Real Example: API Gateway 4xx vs 5xx Analysis
ECS/Fargate Container Logs
ECS Log Stream Format
Query ECS Container Logs
ECS Task Failures
ECS Container Resource Issues
Real Example: ECS Service Health Check
RDS Database Logs
RDS Error Log Queries
RDS Slow Query Analysis
Real Example: RDS Connection Issues
VPC Flow Logs
VPC Flow Log Format
Query VPC Flow Logs
VPC Traffic Volume by IP
Real Example: Security Analysis - Rejected Connections
CloudTrail Logs
CloudTrail Event Structure
Query CloudTrail for Errors
CloudTrail Unauthorized Attempts
Real Example: CloudTrail Security Monitoring
Application Load Balancer Logs
ALB Log Format
Query ALB Access Logs
ALB Performance Analysis
Real Example: ALB Error Analysis
ElastiCache Logs
Query ElastiCache Slow Logs
ElastiCache Connection Issues
CodeBuild Logs
Query CodeBuild Failures
CodeBuild Phase Duration
Step Functions Logs
Query Step Functions Failures
Cross-Service Correlation Patterns
Pattern: Trace Request Across Services
Pattern: API Gateway โ Lambda โ RDS
Service-Specific Best Practices
Lambda Best Practices
API Gateway Best Practices
RDS Best Practices
ECS Best Practices
Key Takeaways
PreviousPart 3: Advanced Query Operations and FunctionsNextPart 5: Building Observability Dashboards with CloudWatch
Last updated