A company is migrating its on-premises applications to AWS. They have a requirement to centralize all application and system logs from both their existing on-premises servers and new Amazon EC2 instances into a single AWS service for unified monitoring and analysis. The solution must support real-time ingestion and querying capabilities.
- ASend on-premises logs to an S3 bucket and EC2 logs to CloudWatch Logs, then use Amazon Athena to query all logs.
- BDeploy a custom Fluentd/Fluent Bit cluster on-premises and within AWS to collect logs and forward them to Amazon OpenSearch Service.
- CInstall the CloudWatch agent on both on-premises servers and EC2 instances to send logs to CloudWatch Logs, then use CloudWatch Logs Insights for querying.
- DUse AWS DataSync to transfer on-premises logs to Amazon EFS, and configure EC2 instances to write logs directly to EFS.
Show answer & explanationAnswer & explanation
Correct answer: C. Install the CloudWatch agent on both on-premises servers and EC2 instances to send logs to CloudWatch Logs, then use CloudWatch Logs Insights for querying.
The CloudWatch agent is specifically designed to collect logs and metrics from both on-premises servers and EC2 instances and send them to CloudWatch Logs. CloudWatch Logs provides real-time ingestion, and CloudWatch Logs Insights offers powerful, serverless querying capabilities across all centralized log data, fulfilling all requirements with a native AWS solution.
Why the other options are wrong
- A. While S3 can store logs, CloudWatch Logs is better for real-time ingestion and CloudWatch Logs Insights offers more integrated querying for log data than Athena for this specific scenario.
- B. While OpenSearch Service is a valid log analysis tool, deploying and managing custom Fluentd/Fluent Bit clusters adds significant operational overhead compared to the managed CloudWatch agent and CloudWatch Logs service.
- D. EFS is a file system, not a log ingestion and analysis service. This approach lacks real-time querying capabilities and is not designed for centralized log management.
CloudWatch Agent for Hybrid Log Collection
The CloudWatch agent is a unified agent that can collect logs and metrics from both AWS EC2 instances and on-premises servers, sending them to Amazon CloudWatch.
- Supports Linux and Windows operating systems.
- Collects application logs and system logs.
- Enables centralized logging for hybrid environments.
- Configurable via JSON files for specific log paths.
Memory trick: CloudWatch Agent is the 'Bridge' for logs from on-prem to cloud insights.