rights reserved. ログの構造化によるクエリの差 35 fields @timestamp, @message | filter user = ”ryuji.hori" and action = "login" and status = "success" | stats count() as login_success_count { "timestamp": "2024-08-03T12:00:00Z", "user": "ryuji.hori", "action": "login", "status": "success” } 非構造化ログ 構造化されたログ 2024-08-03T12:00:00Z ryuji.hori performed login action with status success クエリ クエリ fields @timestamp, @message | parse @message " * * performed * action with status *" as user, action, status | filter user = ”ryuji.hori" and action = "login" and status = "success” | stats count() as login_success_count ⽣成AIでクエリを⾃動⽣成も・・ハンズオンでどうぞ CloudWatch Logs Insights