Cloudwatch Logs insight query for Cloudfront logs

0

Can any one please help in setting up the proper query to fetch 4xx and 5xx errors coming from Origin and the Edge on Cloudwatch Logs Insights ?

We are pushing out the logs from S3 to Cloudwatch Log group. Please help us with proper query here

Dhaval
已提問 9 個月前檢視次數 419 次
3 個答案
0

Have you already gone through this blog post, where same things is discussed.

Hope you find this helpful.

Comment here if you are looking for something else, happy to help further.

Abhishek

profile pictureAWS
專家
已回答 9 個月前
0

Thanks for this blog post.Am aware of this post.Based on this only I created this Log group. But it would be helpful if I get help in modifying the query ? Based on 4xx,5xx errors and filtering the logs based on the URL (exact match)

Dhaval
已回答 9 個月前
0

I have created a query, but can't we get Origin IP details ? for the below set of metric from Cloudfront ? c_ip is only for Client IP,what about Origin IP ?

[date, time, x_edge_location, sc_bytes, c_ip, cs_method, Host, cs_uri_stem, sc_status, cs_referer, cs_User_Agent, us_uri_query, Cookie, x_edge_result_type=CapacityExceeded, x_edge_request_id, x_host_header, cs_protocol, cs_bytes, time_taken, x_forwarded_for, ssl_protocol, ssl_cipher, x_edge_response_result_type, cs_protocol_version, fle_status, fle_encrypted_fields, c_port, time_to_first_byte, x_edge_detailed_result_type, sc_content_type, sc_content_len, sc_range_start, sc_range_end ]

Dhaval
已回答 9 個月前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南