Business
Jobs
  • About Us
  • Solutions
    • Job Postings
      Post your job and receive qualified candidates in 48h.
    • Candidate Assessments
      500+ technical and psychological tests, plus anti-fraud.
    • Headhunting
      Tailor-made executive search from start to finish.
    • Payroll + EOR
      Payroll dispersal and EOR across 15+ LATAM countries.
  • Pricing
  • Jobs

0

298
Views
Filtering AWS CloudWatch raw log events by multiple values / AWS CLI

Given the following query on CloudWatch that extracts logs with messages including "entry 1456" (where 1456 is an ID) how should I extend this to take multiple IDs and what is the corresponding CLI command?

fields  @message
| filter @message like "entry 1456"
| limit 10

To clarify I'd like to filter with multiple IDs, for instance "like 1456|1257|879". But not sure of the format of regex in such case.

And I assume the corresponding CLI command will be sth like:

aws logs filter-log-events 
--log-group-name group_name
--app
--filter-pattern ........

Just want to make sure of the best way to formulate this.

over 4 years ago · Santiago Trujillo
2 answers
Answer question

0

The syntax would be:

fields  @message
| filter @message like /entry [1456|1257]/
| limit 10

You could also parse the logline first and extract the value, like this:

fields  @message
| parse @message /.*entry (?<id>\d+).*/
| filter id in [1257, 1456]
| limit 10

Now for the CLI, you would not use the filter-log-events, but the start-query and get-query-results.

over 4 years ago · Santiago Trujillo Report

0

Just for visibility and copy/paste ability the current correct syntax is :

fields @message
| filter @message like /entry (1457|1458)/
| limit 20
over 4 years ago · Santiago Trujillo Report
Answer question
Find remote jobs

Discover the new way to find a job!

Top jobs
Top job categories
Business
Post vacancy Pricing Sales
Legal
Terms and conditions Privacy policy
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Show me some job opportunities
There's an error!