Use Lambda over a CloudWatch Logs stream to count unique users per client

Answer Correct answer: D — Process the CloudWatch Logs stream with Lambda and put user name and client name dimensions into custom metrics, with no application changes.

A company wants to record key performance indicators (KPIs) from its application as part of a strategy to convert to a user-based licensing schema. The application is a multi-tier application with a web-based UI. The company saves all log files to Amazon CloudWatch by using the CloudWatch agent. All logins to the application are saved in a log file. As part of the new license schema, the company needs to find out how many unique users each client has on a daily basis, weekly basis, and monthly basis. Which solution will provide this information with the LEAST change to the application?

  1. Configure an Amazon CloudWatch Logs metric filter that saves each successful login as a metric. Configure the user name and client name as dimensions for the metric.
  2. Change the application logic to make each successful login generate a call to the AWS SDK to increment a custom metric that records user name and client name dimensions in CloudWatch.
  3. Configure the CloudWatch agent to extract successful login metrics from the logs. Additionally, configure the CloudWatch agent to save the successful login metrics as a custom metric that uses the user name and client name as dimensions for the metric.
  4. Configure an AWS Lambda function to consume an Amazon CloudWatch Logs stream of the application logs. Additionally, configure the Lambda function to increment a custom metric in CloudWatch that uses the user name and client name as dimensions for the metric. Correct Answer

Community Votes

D
53%
A
47%

53% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A metric filter can count pattern occurrences but cannot deduplicate, so only a Lambda function that reads the log stream can compute unique users, and it does so without touching application code.

The company needs unique user counts per client for daily, weekly, and monthly periods, and all log files already go to CloudWatch with logins recorded. The requirement is the least possible change to the application itself.

Believing a CloudWatch Logs metric filter can count unique users. Metric filters extract values and emit metrics, but they have no deduplication or distinct-count capability, so repeated logins from the same user inflate the result.

Community Discussion (13 comments)

itsjunukim 👍 1 Selected: D
Metric Filters only provide simple pattern counting functionality and cannot handle duplicate users.
GabrielShiao 👍 1 Selected: A
Both A and B are workable. A is the simplest and has no code development effort
0b43291 👍 3 Selected: D
With https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/MonitoringLogData.html the documentation states that CloudWatch Logs metric filters can extract and publish metrics based on log data, but the dimensions for these metrics are limited to the following: LogGroupName LogStreamName Namespace (optional) There is no mention of the ability to use custom dimensions like user name or client name with CloudWatch Logs metric filters. Given this limitation, the solution that would provide the required information with the least change to the application is: D. Configure an AWS Lambda function to consume an Amazon CloudWatch Logs stream of the application logs. Additionally, configure the Lambda function to increment a custom metric in CloudWatch that uses the user name and client name as dimensions for the metric.
AzureDP900 👍 3
Option A involves configuring a CloudWatch Logs metric filter to extract login metrics from log files. This approach can provide the required KPIs with minimal changes to the application, as it does not require modifying the application code or adding additional services. The solution also uses dimensions to capture user name and client name information, which will help identify unique users for each client on a daily, weekly, and monthly basis.
Danm86 👍 1
Answer seems to be option D. Metric Filters can only count the occurrence of a pattern in the log, they cannot extract specific data fields like user name or client name. Metric Filters do not automatically create custom metrics in CloudWatch. They only send the counted values to an existing metric.
chris_spencer 👍 2 Selected: D
was at first for A but then for D.. ChatGPT is also for D: D: This option provides the most flexibility and capability for processing data. AWS Lambda can process the incoming log stream to apply more complex logic, such as checking for and ignoring duplicate entries within a set time frame (daily, weekly, monthly) before incrementing the metrics. This allows for the implementation of logic to ensure that users are only counted once per period, effectively tracking unique logins. Conclusion: Among the given options, Option D using an AWS Lambda function is best equipped to handle the requirement of counting unique user logins accurately over specified periods. Lambda functions offer the flexibility to implement any necessary logic to filter duplicates and manage counts over time, aligning with the need to track unique users on a daily, weekly, and monthly basis.
Syre 👍 4 Selected: D
A is not because Metric filters can't directly solve the problem of counting unique users across different time periods. They can count how many logins happened, but not how many distinct users logged in during those time periods.
thotwielder 👍 4 Selected: A
https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/MonitoringLogData.html
VerRi 👍 1 Selected: A
With existing logs, we don't have to make changes to the application.
pangchn 👍 1 Selected: A
I would go for A https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/MonitoringPolicyExamples.html
AWSPro1234 👍 2
Answer is C.
Dgix 👍 2 Selected: A
A is the correct answer: it has the least changes to the application. C and D are rubbish.
CMMC 👍 1 Selected: C
No app code change by configuring the agent to extract & save successful login metrics as custom metrics with user name and client name dimensions. #A and #B requires app changes. #D needs additional lamba infra and increase complexity

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A Lambda function subscribed to the CloudWatch Logs stream parses the login records, maintains its own set or store of seen user and client combinations for the daily, weekly, and monthly windows, and puts the unique counts into CloudWatch custom metrics. The application keeps writing logs exactly as it does today, so the change to the application is effectively zero.

Why the Other Options Are Wrong

A: A metric filter counts matching lines and can extract values as dimensions, but it cannot deduplicate, so a user who logs in repeatedly is counted many times instead of once. B: This requires modifying application logic to call the AWS SDK, which is the most invasive option and the opposite of least change. C: The CloudWatch agent collects standard metrics and logs, but it cannot create custom metrics with dimensions extracted from log content, so it cannot produce these unique-count metrics.

Community Comment Notes

This was a narrow 50 to 45 community split between D and A. The deciding argument came from the AWS documentation on monitoring log data, which confirms metric filters publish metrics from log data but perform no aggregation beyond pattern counting, so unique counting needs Lambda.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide