Skip to content

aws.cloudwatch.get_insight_rule_report

Example SQL Queries

SELECT * FROM
aws.cloudwatch.get_insight_rule_report
WHERE
"rule_name" = 'VALUE'
AND "start_time" = 'VALUE'
AND "end_time" = 'VALUE'
AND "period" = 'VALUE';

Description

This operation returns the time series data collected by a Contributor Insights rule. The data includes the identity and number of contributors to the log group.

You can also optionally return one or more statistics about each data point in the time series. These statistics can include the following:

  • UniqueContributors -- the number of unique contributors for each data point.

  • MaxContributorValue -- the value of the top contributor for each data point. The identity of the contributor might change for each data point in the graph.

    If this rule aggregates by COUNT, the top contributor for each data point is the contributor with the most occurrences in that period. If the rule aggregates by SUM, the top contributor is the contributor with the highest sum in the log field specified by the rule's Value, during that period.

  • SampleCount -- the number of data points matched by the rule.

  • Sum -- the sum of the values from all contributors during the time period represented by that data point.

  • Minimum -- the minimum value from a single observation during the time period represented by that data point.

  • Maximum -- the maximum value from a single observation during the time period represented by that data point.

  • Average -- the average value from all contributors during the time period represented by that data point.

Table Definition

Column NameColumn Data Type
end_time Required Input Column

The end time of the data to use in the report. When used in a raw HTTP Query API, it is formatted as yyyy-MM-dd'T'HH:mm:ss. For example, 2019-07-01T23:59:59.

TIMESTAMP_S
period Required Input Column

The period, in seconds, to use for the statistics in the InsightRuleMetricDatapoint results.

BIGINT
rule_name Required Input Column

The name of the rule that you want to see data from.

VARCHAR
start_time Required Input Column

The start time of the data to use in the report. When used in a raw HTTP Query API, it is formatted as yyyy-MM-dd'T'HH:mm:ss. For example, 2019-07-01T23:59:59.

TIMESTAMP_S
max_contributor_count Input Column

The maximum number of contributors to include in the report. The range is 1 to 100. If you omit this, the default of 10 is used.

BIGINT
metrics Input Column

Specifies which metrics to use for aggregation of contributor values for the report. You can specify one or more of the following metrics:

  • UniqueContributors -- the number of unique contributors for each data point.

  • MaxContributorValue -- the value of the top contributor for each data point. The identity of the contributor might change for each data point in the graph.

    If this rule aggregates by COUNT, the top contributor for each data point is the contributor with the most occurrences in that period. If the rule aggregates by SUM, the top contributor is the contributor with the highest sum in the log field specified by the rule's Value, during that period.

  • SampleCount -- the number of data points matched by the rule.

  • Sum -- the sum of the values from all contributors during the time period represented by that data point.

  • Minimum -- the minimum value from a single observation during the time period represented by that data point.

  • Maximum -- the maximum value from a single observation during the time period represented by that data point.

  • Average -- the average value from all contributors during the time period represented by that data point.

VARCHAR[]
Show child fields
metrics[]
order_by Input Column

Determines what statistic to use to rank the contributors. Valid values are Sum and Maximum.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

aggregate_value

The sum of the values from all individual contributors that match the rule.

DOUBLE
aggregation_statistic

Specifies whether this rule aggregates contributor data by COUNT or SUM.

VARCHAR
approximate_unique_count

An approximate count of the unique contributors found by this rule in this time period.

BIGINT
contributors

An array of the unique contributors found by this rule in this time period. If the rule contains multiple keys, each combination of values for the keys counts as a unique contributor.

STRUCT(
"keys" VARCHAR[],
"approximate_aggregate_value" DOUBLE,
"datapoints" STRUCT(
"timestamp" TIMESTAMP_S,
"approximate_value" DOUBLE
)[]
)[]
Show child fields
contributors[]
Show child fields
contributors[].approximate_aggregate_value

An approximation of the aggregate value that comes from this contributor.

contributors[].datapoints[]
Show child fields
contributors[].datapoints[].approximate_value

The approximate value that this contributor added during this timestamp.

contributors[].datapoints[].timestamp

The timestamp of the data point.

contributors[].keys[]
key_labels

An array of the strings used as the keys for this rule. The keys are the dimensions used to classify contributors. If the rule contains more than one key, then each unique combination of values for the keys is counted as a unique contributor.

VARCHAR[]
Show child fields
key_labels[]
metric_datapoints

A time series of metric data points that matches the time period in the rule request.

STRUCT(
"timestamp" TIMESTAMP_S,
"unique_contributors" DOUBLE,
"max_contributor_value" DOUBLE,
"sample_count" DOUBLE,
"average" DOUBLE,
"sum" DOUBLE,
"minimum" DOUBLE,
"maximum" DOUBLE
)[]
Show child fields
metric_datapoints[]
Show child fields
metric_datapoints[].average

The average value from all contributors during the time period represented by that data point.

This statistic is returned only if you included it in the Metrics array in your request.

metric_datapoints[].max_contributor_value

The maximum value provided by one contributor during this timestamp. Each timestamp is evaluated separately, so the identity of the max contributor could be different for each timestamp.

This statistic is returned only if you included it in the Metrics array in your request.

metric_datapoints[].maximum

The maximum value from a single occurence from a single contributor during the time period represented by that data point.

This statistic is returned only if you included it in the Metrics array in your request.

metric_datapoints[].minimum

The minimum value from a single contributor during the time period represented by that data point.

This statistic is returned only if you included it in the Metrics array in your request.

metric_datapoints[].sample_count

The number of occurrences that matched the rule during this data point.

This statistic is returned only if you included it in the Metrics array in your request.

metric_datapoints[].sum

The sum of the values from all contributors during the time period represented by that data point.

This statistic is returned only if you included it in the Metrics array in your request.

metric_datapoints[].timestamp

The timestamp of the data point.

metric_datapoints[].unique_contributors

The number of unique contributors who published data during this timestamp.

This statistic is returned only if you included it in the Metrics array in your request.