You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何调整CloudWatch Insights查询以生成支持可视化的聚合数据

问题描述

我尝试解析CloudWatch日志以构建饼图、柱状图等可视化图表,日志数据为JSON格式,示例如下:

{
    "feature": "Feature 1",
    "container": "TestContainer",
    "user": {
        "mail": "email@gmail.com",
        "org": "temp_org",
        "external": true
    }
}

{
    "feature": "Feature 2",
    "container": "TestContainer1",
    "user": {
        "mail": "email1@gmail.com",
        "org": "temp1_org",
        "external": true
    }
}

我希望基于feature、container、user等字段进行过滤,例如统计“Feature 1”的请求数量。当前使用的CloudWatch Logs Insights查询如下:

fields @timestamp, @message, feature, container, user
| filter feature = "Feature 1"
| stats count(*) as Number_of_Request by feature

该查询能返回正确的过滤结果,但因仅输出单个数值而非时序数据,无法生成正确的可视化图表。请问如何将其与总请求数进行聚合以生成符合要求的可视化数据?

解决方案

1. 生成时序类可视化数据(折线/柱状图)

要生成带时间维度的可视化,核心是将统计结果按时间窗口分组,让CloudWatch识别到时序维度。以下查询可同时输出各时间窗口内的总请求数与Feature 1的请求数:

fields @timestamp, feature
| stats 
    count(*) as Total_Requests,
    sum(case when feature = "Feature 1" then 1 else 0 end) as Feature1_Requests
 by bin(5m)  -- 时间窗口可按需调整,比如1m/1h等

返回结果会按指定时间间隔展示两组数据,直接支持生成对比柱状图或折线图。

2. 生成占比类可视化数据(饼图/环形图)

如果需要展示各feature的请求占比,直接统计所有feature的请求数即可:

fields feature
| stats count(*) as Request_Count by feature

CloudWatch会自动将结果转换为饼图。若只想突出Feature 1与其他请求的占比,可将数据合并为两组:

fields feature
| stats count(*) as Request_Count 
 by case when feature = "Feature 1" then "Feature 1" else "Other Features" end as Feature_Category

3. 多维度过滤的时序统计

如果需要结合container、user等字段过滤,同时保留时序维度,比如统计TestContainer内Feature 1的请求数与容器总请求数:

fields @timestamp, feature, container
| filter container = "TestContainer"
| stats 
    count(*) as Total_Container_Requests,
    sum(case when feature = "Feature 1" then 1 else 0 end) as Feature1_Container_Requests
 by bin(10m)

内容的提问来源于stack exchange,提问作者nbe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 21:04:56