Cloudwatch Logs insight query for Cloudfront logs

0

Can any one please help in setting up the proper query to fetch 4xx and 5xx errors coming from Origin and the Edge on Cloudwatch Logs Insights ?

We are pushing out the logs from S3 to Cloudwatch Log group. Please help us with proper query here

3 Answers
0

Have you already gone through this blog post, where same things is discussed.

Hope you find this helpful.

Comment here if you are looking for something else, happy to help further.

Abhishek

profile pictureAWS
EXPERT
answered 8 months ago
0

Thanks for this blog post.Am aware of this post.Based on this only I created this Log group. But it would be helpful if I get help in modifying the query ? Based on 4xx,5xx errors and filtering the logs based on the URL (exact match)

Dhaval
answered 8 months ago
0

I have created a query, but can't we get Origin IP details ? for the below set of metric from Cloudfront ? c_ip is only for Client IP,what about Origin IP ?

[date, time, x_edge_location, sc_bytes, c_ip, cs_method, Host, cs_uri_stem, sc_status, cs_referer, cs_User_Agent, us_uri_query, Cookie, x_edge_result_type=CapacityExceeded, x_edge_request_id, x_host_header, cs_protocol, cs_bytes, time_taken, x_forwarded_for, ssl_protocol, ssl_cipher, x_edge_response_result_type, cs_protocol_version, fle_status, fle_encrypted_fields, c_port, time_to_first_byte, x_edge_detailed_result_type, sc_content_type, sc_content_len, sc_range_start, sc_range_end ]

Dhaval
answered 8 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions