1

我正在从 Cloud watch 获取日志到 Grafana 仪表板。

但是,我无法将其制成面板或仪表板。

我尝试的是去探索检查云观察日志并运行查询"fields @messages"

这是返回值

{
    "version": "0",
    "id": "sadfasdf-sdf-asfd-asdf-a3753e4aa9ae",
    "detail-type": "ECR",
    "source": "aws.ecr",
    "account": "12345",
    "time": "2020-23-29T02:36:48Z",
    "region": "us-east-1",
    "resources": [
        "arn:aws:ecr:us-east-1:XXXXXXXXXXX:repository/repo"
    ],
    "detail": {
        "scan-status": "COMPLETE",
        "repository-name": "my-repo",
        "finding-severity-counts": {
           "CRITICAL": 5,
           "MEDIUM": 3
         },
        "image-digest": "sha256:xxxxxxxxxxx",
        "image-tags": []
    }
}

那么如何编写可以在仪表板或面板中列出以下详细信息的查询。

"finding-severity-counts": {
               "CRITICAL": 5,
               "MEDIUM": 3
             },

我试过类似的东西

stats (detail.finding-severity-counts.CRITICAL) as severity 

但到目前为止没有运气仪表板没有显示任何内容。我也认为上面一次只会显示CRITICAL价值而不是中等。

提前致谢

4

1 回答 1

0

您是否尝试过添加计数?像这样:

stats count(detail.finding-severity-counts.CRITICAL) as severity

于 2021-09-02T10:26:37.403 回答