CloudWatch Logs Insights多日志关联查询:B消息MyValue=0时仅输出A消息求助
Solution for CloudWatch Logs Insights: Match A Messages When Corresponding B Message Has MyValue=0
Here's a working query that will return only the A messages where their paired B message (sharing the same requestid) has MyValue:0:
parse @message "\[INFO\] * requestid *: *" as timestamp, requestid, type, content | parse content "'MyValue':*}" as MyValue if type = "B" | stats collect(@message) as all_messages, any(type = "A") as has_A, any(type = "B" and MyValue = "0") as has_valid_B by requestid | filter has_A and has_valid_B | mv-expand all_messages | filter all_messages like /A:/
How this works step-by-step:
- Parse log fields: Extracts the
timestamp, sharedrequestid, message type (A/B), and content body from each log entry. - Extract MyValue for B messages: Only parses the
MyValuefield from B-type messages (since A messages don't have this field). - Aggregate by requestid: Groups all logs by their shared
requestid, tracking all original log messages, whether an A message exists, and whether a B message withMyValue=0exists. - Filter valid requests: Keeps only request groups that have both an A message and a valid B message (MyValue=0).
- Expand message list: Unpacks the aggregated list of messages for each valid request.
- Keep only A messages: Filters down to just the A-type messages from valid request groups, which is your desired output.
Why your original query failed:
Your initial approach:
filter @message like /A:|B:/ filter MyValue = 0
doesn't work because the second filter drops all entries that don't have a MyValue field—including all A messages. CloudWatch Logs Insights filters act on individual log entries, not grouped/related entries, so you need to first correlate messages by requestid before applying your conditional logic.
Test cases:
- When your B message has
MyValue:0, the query will return the corresponding A message as expected. - When your B message has
MyValue:12, thehas_valid_Bflag will be false, so the request group gets filtered out, resulting in an empty output.
内容的提问来源于stack exchange,提问作者CPB
相关产品推荐
相关产品推荐

