Exemplos de regras do CloudWatch Contributor Insights - Amazon CloudWatch

Exemplos de regras do CloudWatch Contributor Insights

Esta seção contém exemplos que ilustram casos de uso para regras do Contributor Insights.

Logs de fluxo da VPC: transferências de byte por endereço IP de origem e endereço IP de destino

{ "Schema": { "Name": "CloudWatchLogRule", "Version": 1 }, "LogGroupNames": [ "/aws/containerinsights/sample-cluster-name/flowlogs" ], "LogFormat": "CLF", "Fields": { "4": "srcaddr", "5": "dstaddr", "10": "bytes" }, "Contribution": { "Keys": [ "srcaddr", "dstaddr" ], "ValueOf": "bytes", "Filters": [] }, "AggregateOn": "Sum" }

Logs de fluxo da VPC: número mais alto de solicitações HTTPS

{ "Schema": { "Name": "CloudWatchLogRule", "Version": 1 }, "LogGroupNames": [ "/aws/containerinsights/sample-cluster-name/flowlogs" ], "LogFormat": "CLF", "Fields": { "5": "destination address", "7": "destination port", "9": "packet count" }, "Contribution": { "Keys": [ "destination address" ], "ValueOf": "packet count", "Filters": [ { "Match": "destination port", "EqualTo": 443 } ] }, "AggregateOn": "Sum" }

Logs de fluxo da VPC: conexões TCP rejeitadas

{ "Schema": { "Name": "CloudWatchLogRule", "Version": 1 }, "LogGroupNames": [ "/aws/containerinsights/sample-cluster-name/flowlogs" ], "LogFormat": "CLF", "Fields": { "3": "interfaceID", "4": "sourceAddress", "8": "protocol", "13": "action" }, "Contribution": { "Keys": [ "interfaceID", "sourceAddress" ], "Filters": [ { "Match": "protocol", "EqualTo": 6 }, { "Match": "action", "In": [ "REJECT" ] } ] }, "AggregateOn": "Sum" }

Respostas do Route 53 NxDomain por endereço de origem

{ "Schema": { "Name": "CloudWatchLogRule", "Version": 1 }, "AggregateOn": "Count", "Contribution": { "Filters": [ { "Match": "$.rcode", "StartsWith": [ "NXDOMAIN" ] } ], "Keys": [ "$.srcaddr" ] }, "LogFormat": "JSON", "LogGroupNames": [ "<loggroupname>" ] }

Consultas do Route 53 Resolver por nome de domínio

{ "Schema": { "Name": "CloudWatchLogRule", "Version": 1 }, "AggregateOn": "Count", "Contribution": { "Filters": [], "Keys": [ "$.query_name" ] }, "LogFormat": "JSON", "LogGroupNames": [ "<loggroupname>" ] }

Consultas do Route 53 Resolver por tipo de consulta e endereço de origem

{ "Schema": { "Name": "CloudWatchLogRule", "Version": 1 }, "AggregateOn": "Count", "Contribution": { "Filters": [], "Keys": [ "$.query_type", "$.srcaddr" ] }, "LogFormat": "JSON", "LogGroupNames": [ "<loggroupname>" ] }