AWS Certified DevOps Engineer – ProfessionalMonitoring and LoggingEasy

A development team is deploying a new microservices application on AWS using Amazon ECS and AWS Fargate. They need a centralized logging solution that can collect logs from multiple containers, store them durably, and allow for real-time analysis and querying. The solution should also be cost-effective and require minimal operational overhead. Which AWS service combination best meets these requirements?

  1. AAmazon CloudWatch Logs for log collection and storage, and Amazon CloudWatch Logs Insights for querying.
  2. BAmazon Kinesis Data Firehose for log ingestion, Amazon OpenSearch Service for indexing and analysis, and Amazon S3 for archival.
  3. CAWS Systems Manager Agent for log collection, Amazon SQS for buffering, and a self-managed ELK stack on EC2 for analysis.
  4. DAmazon S3 for log storage, AWS Lambda for processing, and Amazon Athena for querying.
Show answer & explanation

Correct answer: A. Amazon CloudWatch Logs for log collection and storage, and Amazon CloudWatch Logs Insights for querying.

Amazon CloudWatch Logs provides a fully managed service for centralizing logs from various AWS services, including ECS/Fargate. CloudWatch Logs Insights offers a powerful, interactive query engine for real-time analysis without needing to manage additional infrastructure.

Why the other options are wrong

  • B. This is a robust solution but involves more services and potentially higher operational complexity and cost than simply using CloudWatch Logs and Insights for the described needs.
  • C. This option introduces self-managed components (ELK stack) and additional agents, conflicting with the requirement for minimal operational overhead.
  • D. While possible, this approach requires more custom development for log processing and real-time querying compared to CloudWatch Logs Insights.

CloudWatch Logs Insights

A fully integrated, interactive query service within Amazon CloudWatch Logs that allows you to analyze and troubleshoot logs without managing any infrastructure.

  • Queries logs stored in CloudWatch Logs.
  • Supports powerful query language for filtering and aggregation.
  • No servers to manage, pay-per-query pricing model.

Memory trick: Containers Logged Centrally, Quickly Query Insights.

More Monitoring and Logging questions