Currently, in the AWS console, I do not think this exact feature is there where you can see the log above or below the event that you are looking for. However, you can achieve the same with the help of AWS CLI.
I will try to explain the process stepwise.
Step1: You first need to list the name of all the log streams present in the specified log group. To do so, you need to execute this.
Note that I am assuming that you have the required flag (--region) configured in ~/.aws/config file and your EC2 instance has the required permission to execute this command.
aws logs describe-log-streams --log-group-name /aws/lambda/your-log-group-name
The sample output of this would be
{
"logStreams": [
{
"creationTime": 1555419320137,
"lastEventTimestamp": 1555419320192,
"logStreamName": "2019/04/16/[$LATEST]589f67272fb74720a39c26761d27677d",
"firstEventTimestamp": 1555419320192,
"uploadSequenceToken": "49592576081603401156387322860116873098580931963181347106",
"storedBytes": 371,
"lastIngestionTime": 1555419335277,
"arn": "arn:aws:logs:ap-southeast-1:7442576962489:log-group:/aws/lambda/your-log-group-name:log-stream:2019/04/16/[$LATEST]589f67272fb74720a39c26761d27677d"
}
]
}
Step2: You need to fetch the logStreamName from the above output JSON. Once you know the stream name, you need to find all the log corresponding to this log stream. To do so, you need to execute this:
aws logs get-log-events --log-group-name /aws/lambda/your-log-group-name --log-stream-name 2019/04/16/[\$LATEST]589f67272fb74720a39c26761d27677d
Please note that i have put (escape sequence) before the $ symbol in the log stream name. If you do not do this you will get this error
An error occurred (ResourceNotFoundException) when calling the GetLogEvents operation: The specified log stream does not exist.
The sample output of this would be:
{
"nextBackwardToken": "b/34867571926926708897842553944026580452662164381436805120",
"nextForwardToken": "f/34867572103816219812587456720876035042399810347687804938",
"events": [
{
"ingestionTime": 1563516014935,
"message": "[INFO]\t2019-07-19T05:59:59.947Z\t1dc366b5-d802-4947-931d-8801d6d133dd\tThe length of edits query object is 73067\n",
"timestamp": 1563515999947
},
{
"ingestionTime": 1563516014935,
"message": "REPORT RequestId: 1dc366b5-d802-4947-931d-8801d6d133dd\tDuration: 7931.94 ms\tBilled Duration: 8000 ms \tMemory Size: 1024 MB\tMax Memory Used: 393 MB\t\n",
"timestamp": 1563516007802
}
]
}
Please note that each event in the log stream would have ingestionTime, message, and timestamp. You can redirect the output of this command in a file and use the appropriate grep operation.
This is from the CLI perspective. But you can also get some help in the console itself.
you will be able to see all the events which are matching to your search string and the corresponding log stream name (This will happen when you click on the Search Log Group under a specific log group). You need to click on the Log stream link and you will be able to see all the log in that particular Log stream.
I understand that you will not be able to see all of them on one page only, you need to click on each of the log stream links to see the log.
Hope this helps.