AWS Certified DevOps Engineer – ProfessionalMonitoring and LoggingMedium
A media streaming company uses Amazon CloudFront to deliver content globally. They need to analyze user behavior, content popularity, and identify potential bot activity by examining access logs. The volume of logs is extremely high, and the analysis needs to be performed ad-hoc using standard SQL queries without provisioning or managing any servers. Which solution should they choose?
- AStream CloudFront access logs to Amazon Kinesis Data Firehose and then to Amazon OpenSearch Service for analysis.
- BEnable CloudFront access logs to an S3 bucket and use Amazon Athena to query the logs.
- CUse AWS WAF to block malicious traffic and analyze its logs with AWS CloudTrail.
- DConfigure CloudFront to send access logs to Amazon CloudWatch Logs and use CloudWatch Logs Insights.
Show answer & explanationAnswer & explanation
Correct answer: B. Enable CloudFront access logs to an S3 bucket and use Amazon Athena to query the logs.
Enabling CloudFront access logs to an S3 bucket is the standard way to store these logs. Amazon Athena is a serverless query service that allows running standard SQL queries directly on data stored in S3, making it ideal for ad-hoc analysis of large volumes of CloudFront logs without managing any infrastructure. This solution is cost-effective and meets the requirements for SQL-based ad-hoc analysis.
Why the other options are wrong
- A. While OpenSearch Service can analyze logs, it requires provisioning and managing clusters, which goes against the 'without provisioning or managing any servers' requirement. Athena is serverless.
- C. AWS WAF is for security, not for general user behavior or content popularity analysis from CloudFront access logs. CloudTrail logs API calls, not CloudFront access patterns.
- D. CloudWatch Logs Insights is good for general log analysis, but Athena is often more performant and cost-effective for large-scale, ad-hoc SQL queries on S3-stored CloudFront logs.
CloudFront Logs with Athena
A serverless solution for analyzing large volumes of Amazon CloudFront access logs stored in S3 using standard SQL queries with Amazon Athena.
- CloudFront logs are delivered to S3.
- Athena queries data directly in S3, no data movement.
- Serverless, pay-per-query, ideal for ad-hoc analysis.
Memory trick: CloudFront to S3, then Athena's SQL magic.