AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationMedium

A SysOps administrator needs to analyze detailed application logs from multiple Amazon EC2 instances for troubleshooting and compliance, including logs that are not automatically collected by CloudWatch (e.g., custom application logs in specific directories). The solution must centralize these logs and allow for real-time querying. Which approach is most suitable?

  1. AInstall the CloudWatch agent on each EC2 instance and configure it to collect custom application logs, then send them to CloudWatch Logs. Use CloudWatch Logs Insights for querying.
  2. BSet up an Amazon S3 bucket with a lifecycle policy to receive logs from each EC2 instance via SCP and use S3 Select for querying.
  3. CUse AWS Systems Manager Distributor to deploy a custom log shipping script to each EC2 instance that pushes logs directly to an Amazon OpenSearch Service domain.
  4. DConfigure Amazon Kinesis Firehose to ingest logs from each EC2 instance and deliver them to an Amazon S3 bucket. Use Amazon Athena for querying.
Show answer & explanation

Correct answer: A. Install the CloudWatch agent on each EC2 instance and configure it to collect custom application logs, then send them to CloudWatch Logs. Use CloudWatch Logs Insights for querying.

The CloudWatch agent is designed to collect various types of logs, including custom application logs, from EC2 instances and send them to CloudWatch Logs. CloudWatch Logs Insights provides powerful real-time querying capabilities for these centralized logs.

Why the other options are wrong

  • B. SCP (Secure Copy Protocol) is not a standard AWS service for log ingestion, and S3 Select is less suitable for real-time, complex querying of diverse log data compared to CloudWatch Logs Insights.
  • C. Deploying custom scripts for log shipping is higher operational overhead and OpenSearch Service requires more management than CloudWatch Logs for basic log analysis.
  • D. While Kinesis Firehose can ingest logs to S3, using Athena for 'real-time' querying is less efficient for streaming log analysis compared to CloudWatch Logs Insights.

CloudWatch Agent for Custom Logs

The CloudWatch agent is a flexible tool for collecting system-level metrics, custom metrics, and log files from EC2 instances and on-premises servers, sending them to CloudWatch and CloudWatch Logs.

  • Collects both system metrics and log files.
  • Supports custom application logs from specified paths.
  • Integrates directly with CloudWatch Logs for centralization and querying.

Memory trick: Agent collects logs, CloudWatch stores, Insights makes them yours.

More Monitoring, Logging, and Remediation questions