You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS CloudWatch指标过滤器提取日志中userId的方法求助

在AWS CloudWatch指标过滤器中提取日志里的userId

问题场景

需要从发送到CloudWatch的api.log中提取访问应用的用户userId,示例日志条目如下:

2022-12-06T19:13:59.329Z    2a-b0bc-7a79c791f19c    INFO    Validated that user fakeId has access to the following gated roles: create, update and delete

目标提取值为fakeId,此前尝试的几种模式均失败:

[validation="Validated", that="that", user="user", userId, ...]
[,,user="user",userId,...]
[,,user=user,userId,...]

解决方案

当前日志为空格分隔的非结构化文本,CloudWatch指标过滤器的键值对写法(如user="user")仅适用于JSON等结构化日志,因此之前的模式无法生效。正确的做法是按字段位置匹配:

正确的过滤模式

根据日志的字段拆分顺序,user是第6个字段,目标userId是第7个字段,可使用以下任意一种模式:

  1. 精准匹配前缀文本(确保只提取"Validated that user"后的userId):
[,,,"Validated","that","user",userId,...]
  1. 灵活匹配所有包含"user [userId]"的日志(无需限制前缀内容):
[*,*,*,*,*,"user",userId,...]

使用步骤

  1. 进入CloudWatch控制台,定位到目标日志组
  2. 创建指标过滤器,选择该日志组
  3. 在「过滤模式」输入框中填入上述任一模式
  4. 点击「测试模式」,输入示例日志验证是否成功提取fakeId作为userId字段
  5. 设置指标名称、命名空间等参数,完成过滤器创建

内容的提问来源于stack exchange,提问作者Hima Chitalia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 02:55:43