Book Image

Amazon EC2 Cookbook

Book Image

Amazon EC2 Cookbook

Overview of this book

Discover how to perform a complete forensic investigation of large-scale Hadoop clusters using the same tools and techniques employed by forensic experts. This book begins by taking you through the process of forensic investigation and the pitfalls to avoid. It will walk you through Hadoop’s internals and architecture, and you will discover what types of information Hadoop stores and how to access that data. You will learn to identify Big Data evidence using techniques to survey a live system and interview witnesses. After setting up your own Hadoop system, you will collect evidence using techniques such as forensic imaging and application-based extractions. You will analyze Hadoop evidence using advanced tools and techniques to uncover events and statistical information. Finally, data visualization and evidence presentation techniques are covered to help you properly communicate your findings to any audience.
Table of Contents (15 chapters)
Amazon EC2 Cookbook
Credits
About the Authors
About the Reviewer
www.PacktPub.com
Preface
Index

Using CloudWatch Logs


AWS CloudWatch Logs helps you store, monitor, and analyze your application, system and custom logs, centrally. Using CloudWatch Logs you can monitor your logs in near real time for specific errors and exceptions in your application. For example, you might want to monitor exceptions such as NullPointerException, ArrayIndexOutOfBounds, and ArithmeticException in your Java application.

We will need to aggregate the logs from multiple hosts in an environment where instances are added and deleted, dynamically. AWS CloudWatch is not restricted to work with EC2 instances only, it can also be used for on-premise servers and servers hosted on other public clouds. You can analyze your logs and archive them for access later.

You can extract metrics from logs as they come into AWS CloudWatch using the metric filter. For example, you may want to monitor your web server logs for 4xx and 5xx status codes or monitor your server's log files for OS specific error conditions. In addition...