You need to query logs in Cloud Logging to find errors from a specific Compute Engine instance. The instance ID is 'my-instance'. Which query language filter should you use?
Trap 1: resource.type="compute.googleapis.com/Instance" AND…
Incorrect. 'instance' is not a valid field; the correct label is resource.labels.instance_id.
Trap 2: resource.type="gce_instance" AND…
Incorrect. While the resource type and instance_id are correct, severity='ERROR' only matches exact ERROR level, missing higher severity logs. Use severity>=ERROR to include all error-level logs.
Trap 3: resource.type="gce_instance" AND labels."instance_id"="my-instance"…
Incorrect. Uses labels."instance_id" which is not the correct path; it should be resource.labels.instance_id.
- A
resource.type="compute.googleapis.com/Instance" AND instance="my-instance" AND severity="ERROR"
Why it fails: Incorrect. 'instance' is not a valid field; the correct label is resource.labels.instance_id.
- B
resource.type="gce_instance" AND resource.labels.instance_id="my-instance" AND severity="ERROR"
Why it fails: Incorrect. While the resource type and instance_id are correct, severity='ERROR' only matches exact ERROR level, missing higher severity logs. Use severity>=ERROR to include all error-level logs.
- C
resource.type="gce_instance" AND resource.labels.instance_id="my-instance" AND severity>=ERROR
Cloud Logging filters address resources through monitored resource fields, so resource.type="gce_instance" scopes to Compute Engine VMs and resource.labels.instance_id matches the named instance. Adding severity>=ERROR restricts results to error-level entries, satisfying the requirement to find errors from that specific instance.
- D
resource.type="gce_instance" AND labels."instance_id"="my-instance" AND severity="ERROR"
Why it fails: Incorrect. Uses labels."instance_id" which is not the correct path; it should be resource.labels.instance_id.