如何为含点号的JSON属性编写CloudWatch日志筛选器
如何编写CloudWatch筛选器匹配名称含点号的JSON属性?
CloudWatch日志支持使用属性选择器筛选JSON格式的日志数据,官方语法为:{ PropertySelector EqualityOperator String }
示例用法:{ $.eventType = "UpdateTrail" }
但当日志中的JSON属性名包含点号(比如示例事件里的http.method、express.name这类)时,常规的属性选择写法会失效。你尝试的几种方式都存在问题:
- 筛选器报错:
{ $.attributes.http\.method = "POST" } - 筛选器报错:
{ $.attributes["http.method"] = "POST" } - 筛选器无结果:
{ $.attributes.http.method = "POST" }
正确写法
针对带点号的属性名,需要使用单引号包裹属性名,结合方括号语法来编写选择器,正确的筛选器格式如下:
{ $.attributes['http.method'] = "POST" }
用这个筛选器匹配你提供的示例事件(其中attributes.http.method值为POST),就能成功命中目标日志。
示例事件:
{ "traceId": "75e07edf6f50ddf0d4a8239cbe91d60a", "parentId": "f8875623e2e77de4", "name": "request handler - /subscriptions", "id": "7f8b38dcbbb15983", "kind": 0, "timestamp": 1673621283065, "duration": 3, "attributes": { "http.route": "/subscriptions", "express.name": "/subscriptions", "express.type": "request_handler", "http.method": "POST", "http.url": "/subscriptions", "http.body": "{\"foo\":\"bar\"}" }, "status": { "code": 0 }, "events": [], "links": [] }
内容的提问来源于stack exchange,提问作者womcauliff
相关产品推荐
相关产品推荐

