View a markdown version of this page

DescribeFieldIndexes - Amazon CloudWatch Logs

DescribeFieldIndexes

Returns a list of field indexes discovered in log data. By default, the response includes the DEFAULT, CUSTOM, and INACTIVE index categories. To return indexes from other categories, use the indexCategories parameter.

For more information about field index policies, see PutIndexPolicy.

Request Syntax

{ "indexCategories": [ "string" ], "logGroupIdentifiers": [ "string" ], "nextToken": "string" }

Request Parameters

For information about the parameters that are common to all actions, see Common Parameters.

The request accepts the following data in JSON format.

indexCategories

The index categories to return. The following values are supported:

  • DEFAULT: Fields that CloudWatch Logs indexes by default. Examples include @logStream and @data_format.

  • CUSTOM: Fields that you added manually to the field index policy. CloudWatch Logs always indexes these fields. These fields count toward the quota of 20 fields for each log group.

  • AUTO: Fields that CloudWatch Logs indexes automatically based on your query patterns and usage. These fields do not count toward the field index quota. CloudWatch Logs might update these fields based on changes in your query patterns. To keep a field indexed permanently, add it to an account-level or log-group level field index policy.

  • INACTIVE: Fields that CloudWatch Logs indexed before but does not index now. This happens if you remove a field from the field index policy or if CloudWatch Logs automatically selects a different field based on your queries.

If you omit this parameter, the response includes the DEFAULT, CUSTOM, and INACTIVE categories.

For more information about automatically indexed fields and using the AUTO category, see Automatically indexed fields.

Type: Array of strings

Array Members: Maximum number of 4 items.

Valid Values: DEFAULT | CUSTOM | AUTO | INACTIVE

Required: No

logGroupIdentifiers

An array containing the names or ARNs of the log groups that you want to retrieve field indexes for.

Type: Array of strings

Array Members: Minimum number of 1 item. Maximum number of 100 items.

Length Constraints: Minimum length of 1. Maximum length of 2048.

Pattern: [\w#+=/:,.@-]*

Required: Yes

nextToken

The token for the next set of items to return. The token expires after 24 hours.

Type: String

Length Constraints: Minimum length of 1.

Required: No

Response Syntax

{ "fieldIndexes": [ { "fieldIndexName": "string", "firstEventTime": number, "indexCategory": "string", "lastEventTime": number, "lastScanTime": number, "logGroupIdentifier": "string", "type": "string" } ], "nextToken": "string" }

Response Elements

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

fieldIndexes

An array containing the field index information.

Type: Array of FieldIndex objects

nextToken

The token for the next set of items to return. The token expires after 24 hours.

Type: String

Length Constraints: Minimum length of 1.

Errors

For information about the errors that are common to all actions, see Common Error Types.

InvalidParameterException

A parameter is specified incorrectly.

HTTP Status Code: 400

LimitExceededException

You have reached the maximum number of resources that can be created.

HTTP Status Code: 400

OperationAbortedException

Multiple concurrent requests to update the same resource were in conflict.

HTTP Status Code: 400

ResourceNotFoundException

The specified resource does not exist.

HTTP Status Code: 400

ServiceUnavailableException

The service cannot complete the request.

HTTP Status Code: 500

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: