Courseiva
Monitoring and Logging →mediumMultiple Select

Search Across Multiple CloudWatch Log Groups for Error Patterns

A company uses Amazon CloudWatch Logs to store application logs. The DevOps team wants to search across multiple log groups for a specific error pattern. Which TWO options can be used to achieve this? (Choose TWO.)

Quick Answer

The answer is to use CloudWatch Logs Insights or export logs to Amazon S3 and query with Amazon Athena. CloudWatch Logs Insights is purpose-built for searching across multiple CloudWatch log groups for error patterns using its own query language, allowing you to filter, aggregate, and visualize log events without moving data. The export-to-S3-and-Athena option is equally valid because Athena can run SQL queries over the exported log files in S3, making it ideal for large-scale or complex pattern analysis. On the AWS Certified DevOps Engineer Professional DOP-C02 exam, this question tests your ability to distinguish native cross-log-group query tools from single-log-group features like filter patterns or subscription filters. A common trap is choosing CloudWatch Logs filter patterns, which only work within one log group at a time. Memory tip: think “Insights for instant cross-group search, Athena for SQL over S3 archives.”

⚠ Common exam trap

Many candidates think Lambda or Kinesis are suitable for ad-hoc log searching, but they are designed for real-time processing or custom workflows, not for efficient cross-log-group querying like CloudWatch Logs Insights or Athena.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use CloudWatch Logs Insights to run queries across multiple log groups.

Option A is correct because CloudWatch Logs Insights natively supports querying across multiple log groups in a single query — you can select up to 50 log groups in the console or specify multiple log group ARNs/names in the StartQuery API, and use the query syntax (fields, filter, stats, parse) to search for a specific error pattern. Option B is correct because exporting CloudWatch Logs to Amazon S3 (via CreateExportTask or subscription filters) and then querying the exported data with Amazon Athena lets you run SQL across many log groups' data at once, which is a standard approach for cross-log-group searching and analysis. Option C is not correct because installing the CloudWatch Logs agent and tailing logs only reads logs on a single EC2 instance and does not provide cross-log-group search capability. Option D is not correct because a custom Lambda function reading each log group would be a bespoke, inefficient workaround rather than a supported cross-log-group search feature, and it is not the intended solution. Option E is not correct because Kinesis Data Analytics processes streaming data for real-time analytics, not for searching historical log data across multiple CloudWatch log groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use CloudWatch Logs Insights to run queries across multiple log groups.

    Why this is correct

    CloudWatch Logs Insights queries multiple log groups in one request using its query syntax, filtering and aggregating events directly within CloudWatch Logs. This satisfies the requirement to search several log groups for an error pattern without exporting data.

  • ✓

    Export the logs to Amazon S3 and use Amazon Athena to query the logs.

    Why this is correct

    Exporting log data to Amazon S3 and querying it with Athena lets the team run SQL across all exported log groups, matching the error pattern. This satisfies the cross-log-group search requirement using a separate analytics path rather than Logs Insights.

  • ✗

    Install the CloudWatch Logs agent on an EC2 instance and tail the logs.

    Why it's wrong here

    Tailing logs on a single EC2 instance only reads files local to that host, so it cannot search across multiple CloudWatch Logs groups. It is tempting because the CloudWatch Logs agent does ship logs, and would be correct for publishing instance logs into CloudWatch rather than querying them.

  • ✗

    Create a Lambda function that reads logs from each log group and searches for the pattern.

    Why it's wrong here

    A Lambda function reading each log group requires custom pagination, filtering and aggregation code, and cannot run a single cross-group query. It is tempting because Lambda can call FilterLogEvents, and would be correct for automated event-driven processing of one specific log group rather than ad hoc multi-group pattern search.

  • ✗

    Use Amazon Kinesis Data Analytics to process the log streams.

    Why it's wrong here

    Kinesis Data Analytics performs SQL and Apache Flink stream processing on real-time data in motion, so it cannot query logs already stored in CloudWatch Logs. It is tempting because it genuinely handles streaming analytics, and would be correct for transforming or aggregating live Kinesis streams rather than searching historical log groups.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is using Amazon CloudWatch Logs to store application logs. The DevOps team needs to search and analyze logs from multiple EC2 instances in real time. Which TWO services can be used to achieve this? (Choose TWO.)

medium
  • ✓ A.Amazon OpenSearch Service.
  • B.Amazon Athena.
  • C.Amazon QuickSight.
  • D.Amazon Kinesis Data Analytics.
  • ✓ E.CloudWatch Logs Insights.

Why A: CloudWatch Logs can stream logs to Amazon OpenSearch Service for real-time search and analytics. Option E is correct because CloudWatch Logs Insights allows real-time querying of log groups directly within CloudWatch. Option B is incorrect: Amazon Athena is designed for querying data in S3, not for real-time log search from EC2 instances. Option C is incorrect: Amazon QuickSight is a business intelligence service for visualization, not real-time log search. Option D is incorrect: Amazon Kinesis Data Analytics is for analyzing streaming data, not directly searching CloudWatch Logs.

Variation 2. A company is using Amazon CloudWatch Logs to store application logs. The DevOps team needs to search across multiple log groups and visualize trends. Which TWO services can be used together to achieve this?

medium
  • ✓ A.CloudWatch Logs Insights.
  • B.Amazon Elasticsearch Service with Kibana.
  • C.Amazon Athena.
  • D.Amazon QuickSight.
  • ✓ E.CloudWatch Dashboards.

Why A: CloudWatch Logs Insights (A) is correct because it is the purpose-built query engine for CloudWatch Logs that lets you run interactive queries across multiple log groups simultaneously using its own query syntax, and it can aggregate and visualize results as time-series charts, directly satisfying the 'search across multiple log groups and visualize trends' requirement. CloudWatch Dashboards (E) is correct because it is the visualization layer that can display Logs Insights query results (and other CloudWatch metrics) as widgets on a single dashboard, so the two services are designed to be used together for cross-log-group searching plus trend visualization. Amazon Elasticsearch Service with Kibana (B) can search and visualize logs, but it requires exporting/streaming logs to a separate cluster rather than querying CloudWatch Logs directly, so it is not the intended pairing here. Amazon Athena (C) queries data in Amazon S3 via the Glue Data Catalog, not CloudWatch Logs, and Amazon QuickSight (D) is a BI tool for datasets/dashboards rather than a CloudWatch Logs search engine, so neither belongs.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.