SOA-C02 Practice Question: CloudWatch Logs Insights for querying structured…
Multiple microservices each write structured JSON logs to separate CloudWatch log groups. The operations team needs to find all ERROR-level log entries across all log groups for the past 24 hours and count errors by service name. Which approach achieves this with the least operational overhead?
⚠ Common exam trap
The trap here is that candidates may overcomplicate the solution by assuming cross-log-group analysis requires data aggregation pipelines (like Kinesis or S3/Athena), when CloudWatch Logs Insights natively supports querying multiple log groups with a single query, making it the simplest and most cost-effective option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a CloudWatch Logs Insights query selecting all relevant log groups, filter where level = 'ERROR', and use stats count(*) by service
CloudWatch Logs Insights natively supports querying multiple log groups in a single query. By specifying all relevant log groups in the query scope, filtering for `level = 'ERROR'` using the `filter` command, and using `stats count(*) by service`, the operations team can directly aggregate error counts per service without any data movement, additional infrastructure, or manual scripting. This approach has the least operational overhead because it leverages existing CloudWatch capabilities with no setup or maintenance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run a CloudWatch Logs Insights query selecting all relevant log groups, filter where level = 'ERROR', and use stats count(*) by service
Why this is correct
Logs Insights accepts a comma-separated list of log group names (or a log group name prefix pattern) in the query scope. The filter and stats commands work across all selected groups in a single query execution. No additional pipeline or aggregation layer is needed.
- ✗
Export each log group to S3 and run an Athena query joining all exported files
Why it's wrong here
Exporting to S3 is an asynchronous operation (hours for large log groups) and requires setting up Glue tables or Athena schema definitions before querying. For an ad-hoc 24-hour investigation, this approach has far more setup overhead than Logs Insights.
- ✗
Subscribe all log groups to a Kinesis Data Firehose stream and query the aggregated data in OpenSearch
Why it's wrong here
A Kinesis + OpenSearch pipeline is a persistent, always-on log aggregation architecture appropriate for long-term search and dashboarding. For a one-off cross-service query, it requires provisioning and configuring significant infrastructure before any query can be run.
- ✗
Use the AWS CLI to download and grep log events from each log group separately, then sum the results
Why it's wrong here
Using the AWS CLI (e.g., `aws logs filter-log-events` or `get-log-events`) to retrieve log events for a 24-hour window across many log groups requires handling pagination tokens for each group, downloading every matching event over the network, and then writing custom scripts to parse and aggregate error counts locally. This approach is slow, bandwidth-intensive, and error-prone, especially when log volumes are high, because there is no server-side aggregation and the CLI returns raw events. In contrast, CloudWatch Logs Insights executes the filter and `stats count(*) by service` aggregation directly in the CloudWatch Logs service, returning only the final aggregated result so no bulk data transfer or client-side processing is needed.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.