AWS Certified DevOps Engineer – ProfessionalIncident and Event ResponseEasy
A DevOps team manages a critical microservices application on Amazon EKS. They need to implement a robust solution for collecting, analyzing, and alerting on application logs to quickly identify and troubleshoot issues. The solution must be scalable, cost-effective, and provide near real-time insights across multiple clusters. Which approach should the team take?
- ADeploy a Fluent Bit DaemonSet to send logs to Amazon CloudWatch Logs, then use CloudWatch Alarms and Dashboards.
- BConfigure application containers to write logs directly to Amazon S3, and use AWS Athena for querying.
- CUse ECS Exec to access container logs on demand and manually review them.
- DInstall a self-managed Elasticsearch cluster on EC2 instances and use Kibana for visualization.
Show answer & explanationAnswer & explanation
Correct answer: A. Deploy a Fluent Bit DaemonSet to send logs to Amazon CloudWatch Logs, then use CloudWatch Alarms and Dashboards.
This approach uses Fluent Bit as a lightweight log forwarder within EKS, sending logs to CloudWatch Logs for centralized storage and analysis. CloudWatch Alarms can then be set on log patterns, and Dashboards can visualize metrics derived from logs, providing a scalable and cost-effective solution.
Why the other options are wrong
- B. Writing logs directly to S3 and querying with Athena is suitable for archival and ad-hoc analysis but lacks real-time alerting and dashboarding capabilities for operational monitoring.
- C. ECS Exec is for interactive access and debugging, not for centralized, automated log collection and analysis across multiple clusters.
- D. A self-managed Elasticsearch cluster introduces significant operational overhead for maintenance, scaling, and security, which contradicts the goal of a cost-effective and low-management solution compared to managed services.
EKS Log Management with Fluent Bit and CloudWatch
This pattern involves using Fluent Bit as a DaemonSet in EKS to collect container logs and forward them to Amazon CloudWatch Logs for centralized storage, analysis, and alerting.
- Fluent Bit is a lightweight and efficient log processor.
- CloudWatch Logs provides centralized log storage, querying, and alarming.
- Scalable and managed solution for EKS logging.
Memory trick: Fluent Bit gathers logs, CloudWatch stores the stream, Alarms cry out, Dashboards make it gleam.