Skip to content

aws.devops_guru.list_anomalous_log_groups

Example SQL Queries

SELECT * FROM
aws.devops_guru.list_anomalous_log_groups
WHERE
"insight_id" = 'VALUE';

Description

Returns the list of log groups that contain log anomalies.

Table Definition

Column NameColumn Data Type
insight_id Required Input Column

The ID of the insight containing the log groups.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
anomalous_log_groups

The list of Amazon CloudWatch log groups that are related to an insight.

STRUCT(
"log_group_name" VARCHAR,
"impact_start_time" TIMESTAMP_S,
"impact_end_time" TIMESTAMP_S,
"number_of_log_lines_scanned" BIGINT,
"log_anomaly_showcases" STRUCT(
"log_anomaly_classes" STRUCT(
"log_stream_name" VARCHAR,
"log_anomaly_type" VARCHAR,
"log_anomaly_token" VARCHAR,
"log_event_id" VARCHAR,
"explanation" VARCHAR,
"number_of_log_lines_occurrences" BIGINT,
"log_event_timestamp" TIMESTAMP_S
)[]
)[]
)[]
Show child fields
anomalous_log_groups[]
Show child fields
anomalous_log_groups[].impact_end_time

The time the anomalous log events stopped.

anomalous_log_groups[].impact_start_time

The time the anomalous log events began. The impact start time indicates the time of the first log anomaly event that occurs.

anomalous_log_groups[].log_anomaly_showcases[]
Show child fields
anomalous_log_groups[].log_anomaly_showcases[].log_anomaly_classes[]
Show child fields
anomalous_log_groups[].log_anomaly_showcases[].log_anomaly_classes[].explanation

The explanation for why the log event is considered an anomaly.

anomalous_log_groups[].log_anomaly_showcases[].log_anomaly_classes[].log_anomaly_token

The token where the anomaly was detected. This may refer to an exception or another location, or it may be blank for log anomalies such as format anomalies.

anomalous_log_groups[].log_anomaly_showcases[].log_anomaly_classes[].log_anomaly_type

The type of log anomaly that has been detected.

anomalous_log_groups[].log_anomaly_showcases[].log_anomaly_classes[].log_event_id

The ID of the log event.

anomalous_log_groups[].log_anomaly_showcases[].log_anomaly_classes[].log_event_timestamp

The time of the first occurrence of the anomalous log event.

anomalous_log_groups[].log_anomaly_showcases[].log_anomaly_classes[].log_stream_name

The name of the Amazon CloudWatch log stream that the anomalous log event belongs to. A log stream is a sequence of log events that share the same source.

anomalous_log_groups[].log_anomaly_showcases[].log_anomaly_classes[].number_of_log_lines_occurrences

The number of log lines where this anomalous log event occurs.

anomalous_log_groups[].log_group_name

The name of the CloudWatch log group.

anomalous_log_groups[].number_of_log_lines_scanned

The number of log lines that were scanned for anomalous log events.