How to filter a field using a regex containing characters and digits in AWS Cloudwatch?

Viewed 767

Assuming the log stream contains a message like hello something 1234

The following cloudwatch insights query doesn't return any results.

fields @timestamp, @message
| filter @message like /something 1234/
| sort @timestamp desc
| limit 100

However, using them separately returns results.

fields @timestamp, @message
| filter @message like /1234/
| sort @timestamp desc
| limit 100

Or

fields @timestamp, @message
| filter @message like /something/
| sort @timestamp desc
| limit 100

I'm unable to understand why the regex isn't working as expected

1 Answers

So, this is not an issue with the insights query itself.

But, with how cloudwatch log group displays log messages. Since, I took the displayed message as the source of truth, ended up with this issue.

This is an issue with how HTML displays consecutive spaces.

Consecutive spaces are collapsed by default within a html tag. In this case they are using a <span>. When we expand the line, they use the css property white-space and change the behaviour to not collapse the consecutive spaces.

Reference: https://www.w3.org/TR/CSS2/text.html#white-space-prop

Related