A company runs a web application on Apache HTTP Server on Amazon EC2 instances in an Auto Scaling group. The instances send Apache access logs to an Amazon CloudWatch Logs log group that is set to retain logs for 1 year. The company found that a specific IP address is making suspicious requests. A security engineer needs to analyze the past week of logs to determine how many requests were made from that IP and which URLs were requested, with the least effort. What should the engineer do?
Choose an answer
Tap an option to check your answer.
Correct answer: Use CloudWatch Logs Insights with a custom query to analyze the log group for the IP address and requested URLs..
Why this is the answer
CloudWatch Logs Insights allows for interactive querying and analysis of log data directly within CloudWatch Logs, making it the most efficient and least effort solution for analyzing recent logs. A custom query can quickly filter for the specific IP address and extract requested URLs. Exporting to S3 and using Macie or Glue would involve additional steps and services, increasing effort and time. While OpenSearch Service is powerful for log analysis, setting up a subscription filter and OpenSearch cluster for a one-off analysis of past data is more complex than using Logs Insights.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed