Cloudwatch Logs insight query for Cloudfront logs

0

Can any one please help in setting up the proper query to fetch 4xx and 5xx errors coming from Origin and the Edge on Cloudwatch Logs Insights ?

We are pushing out the logs from S3 to Cloudwatch Log group. Please help us with proper query here

Dhaval
已提问 9 个月前419 查看次数
3 回答
0

Have you already gone through this blog post, where same things is discussed.

Hope you find this helpful.

Comment here if you are looking for something else, happy to help further.

Abhishek

profile pictureAWS
专家
已回答 9 个月前
0

Thanks for this blog post.Am aware of this post.Based on this only I created this Log group. But it would be helpful if I get help in modifying the query ? Based on 4xx,5xx errors and filtering the logs based on the URL (exact match)

Dhaval
已回答 9 个月前
0

I have created a query, but can't we get Origin IP details ? for the below set of metric from Cloudfront ? c_ip is only for Client IP,what about Origin IP ?

[date, time, x_edge_location, sc_bytes, c_ip, cs_method, Host, cs_uri_stem, sc_status, cs_referer, cs_User_Agent, us_uri_query, Cookie, x_edge_result_type=CapacityExceeded, x_edge_request_id, x_host_header, cs_protocol, cs_bytes, time_taken, x_forwarded_for, ssl_protocol, ssl_cipher, x_edge_response_result_type, cs_protocol_version, fle_status, fle_encrypted_fields, c_port, time_to_first_byte, x_edge_detailed_result_type, sc_content_type, sc_content_len, sc_range_start, sc_range_end ]

Dhaval
已回答 9 个月前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则