I'm using a JSON logger which writes my log level property as "@l", so the payload looks like:
{
"@l" : "Debug"
}
I can filter on other properties like this: { $.SomethingElse = "Yolo" }, but I don't know the right syntax to escape the @ character in Cloudwatch. I know how to do it in other tools like Splunk, but the Amazon documentation is lacking.