Cloudwatch Logs config: timestamp_format match

Viewed 192

i am missing the part in the AWS docs where it is described how the timestamp_format is evaluated within a given line.

Here i have a sample log line:

[4138] 2021/07/19 15:20:57.996872 [INF] Listening for client connections on ...

As you can see the datetime info is located in the second column. Does Cloudwatch automagically match the configured timestamp_format pattern within the complete line or does it always assume that the datetime column needs to be in the first column? How can i tell Cloudwatch Agent to use the second column for timestamp_format matching?

1 Answers

From experience, it will find the first timestamp that matches timestamp_format. From what I've read the documentation is a little ambiguous. There are two statements in the documentation that seem to validate this claim.

Under the timestamp_format bullet there is the statement:

If a single log entry contains two time stamps that match the format, the first time stamp is used.

That indicates to me it is looking through the entire log entry for a match, not just parsing the first date field.

Under the multi_line_start_pattern bullet there is the statement:

If you include this field, you can specify {timestamp_format} to use the same regular expression as your timestamp format. Otherwise, you can specify a different regular expression for CloudWatch Logs to use to determine the start lines of multi-line entries.

That indicates to me again timestamp_format used to do pattern matching across the entire log entry.

Related