Cloudwatch Log Insights Query

0

I want to be able to filter the eventName of S3 by PutObject and CopyObject.

fields @timestamp, @message, @logStream, @log, detail.eventName
| sort @timestamp desc
| limit 1000
| filter detail.eventName in ["PutObject", "CopyObject"]

The above query only returns 1 result which I expect more

fields @timestamp, @message, @logStream, @log, detail.eventName
| sort @timestamp desc
| limit 1000
| filter detail.eventName in ["PutObject"]

Also returns one result

fields @timestamp, @message, @logStream, @log, detail.eventName
| sort @timestamp desc
| limit 1000
| filter detail.eventName="PutObject"

Returns a few result which is correct.

How do I set the filter so that the result returns EventName is either PutObject and CopyObject.

profile picture
Lottie
demandé il y a 2 mois523 vues
1 réponse
1
Réponse acceptée

Try this and let me know if it works:

fields @timestamp, @message, @logStream, @log, detail.eventName
| sort @timestamp desc
| limit 1000
| filter (detail.eventName="PutObject" or detail.eventName="CopyObject")
profile picture
EXPERT
répondu il y a 2 mois
profile picture
EXPERT
vérifié il y a 2 mois
  • Yes, it works! What didn't "in" work when applying it to the filter?

Vous n'êtes pas connecté. Se connecter pour publier une réponse.

Une bonne réponse répond clairement à la question, contient des commentaires constructifs et encourage le développement professionnel de la personne qui pose la question.

Instructions pour répondre aux questions