Question 1 · choose 1
Users report that an API backed by an AWS Lambda function was slow during the last hour. In the function's log group, the developer wants the 20 slowest invocations of that hour, with their request IDs, to look them up one by one. Which CloudWatch Logs Insights query should the developer run?
- Afields @requestId, @duration | filter @type = "REPORT" | sort @duration desc | limit 20
- Bfilter @type = "REPORT" | stats max(@duration) by bin(5m)
- Cfields @requestId, @duration | filter @type = "REPORT" | sort @duration asc | limit 20
- Dfields @requestId, @message | filter @message like /ERROR/ | sort @timestamp desc | limit 20
Show the answer and why
Afields @requestId, @duration | filter @type = "REPORT" | sort @duration desc | limit 20
Correct
Lambda REPORT lines carry the discovered @duration and @requestId fields. Sorting by duration in descending order and limiting to 20 returns the slowest invocations.
Bfilter @type = "REPORT" | stats max(@duration) by bin(5m)
Incorrect
stats aggregates into one value per 5-minute bin, so individual invocations and their request IDs are lost.
Cfields @requestId, @duration | filter @type = "REPORT" | sort @duration asc | limit 20
Incorrect
Ascending order returns the shortest durations first, so this lists the 20 fastest invocations, not the slowest.
Dfields @requestId, @message | filter @message like /ERROR/ | sort @timestamp desc | limit 20
Incorrect
This returns the 20 most recent log events that contain ERROR. Slow invocations do not have to log errors.
Lambda REPORT log lines expose @duration, @billedDuration and @maxMemoryUsed; filter, sort and limit turn them into a top-N list.
AWS documentation