Use Lambda over a CloudWatch Logs stream to count unique users per client
A company wants to record key performance indicators (KPIs) from its application as part of a strategy to convert to a user-based licensing schema. The application is a multi-tier application with a web-based UI. The company saves all log files to Amazon CloudWatch by using the CloudWatch agent. All logins to the application are saved in a log file. As part of the new license schema, the company needs to find out how many unique users each client has on a daily basis, weekly basis, and monthly basis. Which solution will provide this information with the LEAST change to the application?
Community Votes
53% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A metric filter can count pattern occurrences but cannot deduplicate, so only a Lambda function that reads the log stream can compute unique users, and it does so without touching application code.
The company needs unique user counts per client for daily, weekly, and monthly periods, and all log files already go to CloudWatch with logins recorded. The requirement is the least possible change to the application itself.
Believing a CloudWatch Logs metric filter can count unique users. Metric filters extract values and emit metrics, but they have no deduplication or distinct-count capability, so repeated logins from the same user inflate the result.
Community Discussion (13 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A Lambda function subscribed to the CloudWatch Logs stream parses the login records, maintains its own set or store of seen user and client combinations for the daily, weekly, and monthly windows, and puts the unique counts into CloudWatch custom metrics. The application keeps writing logs exactly as it does today, so the change to the application is effectively zero.Why the Other Options Are Wrong
A: A metric filter counts matching lines and can extract values as dimensions, but it cannot deduplicate, so a user who logs in repeatedly is counted many times instead of once. B: This requires modifying application logic to call the AWS SDK, which is the most invasive option and the opposite of least change. C: The CloudWatch agent collects standard metrics and logs, but it cannot create custom metrics with dimensions extracted from log content, so it cannot produce these unique-count metrics.Community Comment Notes
This was a narrow 50 to 45 community split between D and A. The deciding argument came from the AWS documentation on monitoring log data, which confirms metric filters publish metrics from log data but perform no aggregation beyond pattern counting, so unique counting needs Lambda.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →