Grafana 查询 cloudwatch 日志
Grafana query for cloud watch logs
我正在从 Cloud watch 获取日志到 Grafana 仪表板。
但是我无法将其制成面板或仪表板。
我尝试去探索检查 Cloud watch 日志和 运行 查询 "fields @messages"
返回值
{
"version": "0",
"id": "sadfasdf-sdf-asfd-asdf-a3753e4aa9ae",
"detail-type": "ECR",
"source": "aws.ecr",
"account": "12345",
"time": "2020-23-29T02:36:48Z",
"region": "us-east-1",
"resources": [
"arn:aws:ecr:us-east-1:XXXXXXXXXXX:repository/repo"
],
"detail": {
"scan-status": "COMPLETE",
"repository-name": "my-repo",
"finding-severity-counts": {
"CRITICAL": 5,
"MEDIUM": 3
},
"image-digest": "sha256:xxxxxxxxxxx",
"image-tags": []
}
}
那么如何编写可以在仪表板或面板中列出以下详细信息的查询。
"finding-severity-counts": {
"CRITICAL": 5,
"MEDIUM": 3
},
我试过
stats (detail.finding-severity-counts.CRITICAL) as severity
但到目前为止,仪表板没有显示任何内容。我也认为上面一次只会显示 CRITICAL
值而不是中值。
提前致谢
你试过给它加计数吗?像这样:
stats count(detail.finding-severity-counts.CRITICAL) as severity
我正在从 Cloud watch 获取日志到 Grafana 仪表板。
但是我无法将其制成面板或仪表板。
我尝试去探索检查 Cloud watch 日志和 运行 查询 "fields @messages"
返回值
{
"version": "0",
"id": "sadfasdf-sdf-asfd-asdf-a3753e4aa9ae",
"detail-type": "ECR",
"source": "aws.ecr",
"account": "12345",
"time": "2020-23-29T02:36:48Z",
"region": "us-east-1",
"resources": [
"arn:aws:ecr:us-east-1:XXXXXXXXXXX:repository/repo"
],
"detail": {
"scan-status": "COMPLETE",
"repository-name": "my-repo",
"finding-severity-counts": {
"CRITICAL": 5,
"MEDIUM": 3
},
"image-digest": "sha256:xxxxxxxxxxx",
"image-tags": []
}
}
那么如何编写可以在仪表板或面板中列出以下详细信息的查询。
"finding-severity-counts": {
"CRITICAL": 5,
"MEDIUM": 3
},
我试过
stats (detail.finding-severity-counts.CRITICAL) as severity
但到目前为止,仪表板没有显示任何内容。我也认为上面一次只会显示 CRITICAL
值而不是中值。
提前致谢
你试过给它加计数吗?像这样:
stats count(detail.finding-severity-counts.CRITICAL) as severity