You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AWS CloudWatch Log Insights中处理无上线日志的摄像头离线告警

解决CloudWatch Log Insights中摄像头离线未恢复的告警查询问题

问题背景

有多台摄像头设备的AWS CloudWatch日志,设备离线或恢复上线时会上报状态。需求是在摄像头离线后60秒未恢复上线时触发告警,但原查询在无上线日志(即lastOnlineTime为空)时无法正常工作,且需要处理CWL查询语言中无直接IF/NULL运算符的场景。

原查询语句:

fields @timestamp, @message, @logStream as log_id
| filter @message like /Device communication error/ or @message like /Device communication established/
| parse @message "Device communication error" as deviceId_offline
| parse @message "*Device communication established" as deviceId_online
| parse @message /.*CameraDecoder \((?<camera_name>[^\)]+)\).*/
| stats min(@timestamp) as firstOfflineTime, max(@timestamp) as lastOnlineTime by camera_name
| filter (lastOnlineTime - firstOfflineTime)  > 60
| sort firstOfflineTime desc

典型日志片段:

2024-11-15 13:10:11.234+00:00 [   167] WARNING    - bdab-b307-4df3-8596  CameraDecoder (testc00013.test0001ev) - Camera 1  Device communication error (NoDataException). Error: GetMediaDataBlock returned no data.

2024-11-15 13:10:18.602+00:00 [   167] INFO       - bdab-b307-4df3-8596  CameraDecoder (testc00013.test0001ev) - Camera 1  Device communication established

解决方案

利用CloudWatch Log Insights的ifelse、isnull和条件聚合函数处理空值场景,核心思路是标记事件类型、分别统计关键时间、针对性计算离线时长:

修改后的查询语句:

fields @timestamp, @message
| filter @message like /Device communication error/ or @message like /Device communication established/
| parse @message /.*CameraDecoder \((?<camera_name>[^\)]+)\).*/
-- 标记日志对应的事件类型(离线/上线)
| fields camera_name, @timestamp, 
         event_type = ifelse(@message like /Device communication error/, 'offline', 'online')
-- 按摄像头统计最后离线、最后上线时间
| stats 
    max(if(event_type='offline', @timestamp, null)) as lastOfflineTime,
    max(if(event_type='online', @timestamp, null)) as lastOnlineTime
    by camera_name
-- 计算离线持续时长:无上线日志或上线晚于离线时,用当前时间计算
| fields 
    camera_name,
    offline_duration = ifelse(
        isnull(lastOnlineTime) or lastOnlineTime < lastOfflineTime,
        now() - lastOfflineTime,
        lastOnlineTime - lastOfflineTime
    )
-- 过滤离线超过60秒的摄像头
| filter offline_duration > 60
| sort lastOfflineTime desc

关键逻辑说明

  1. 事件类型标记:通过ifelse直接根据日志内容标记事件类型,避免原查询中解析空字段的问题。
  2. 条件聚合统计:用max(if(...))分别提取每个摄像头的最后离线、上线时间,空值仅出现在无对应事件的场景。
  3. 空值场景处理:
    • 若lastOnlineTime为空(从未收到上线日志),用查询执行时间now()减去最后离线时间计算时长
    • 若lastOnlineTime早于lastOfflineTime(离线后未恢复),同样用当前时间计算离线时长
  4. 告警过滤:仅保留离线时长超过60秒的记录,满足告警触发条件

内容的提问来源于stack exchange,提问作者AndyM

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 04:47:11