Use Kinesis for real-time forensic log streaming and OpenSearch Service for persistent log analytics

Answer Correct answer: B, D — Amazon Kinesis streams logs in real time with replay, and Amazon OpenSearch Service persists and analyzes them.

A company needs a forensic-logging solution for hundreds of applications running in Docker on Amazon EC2. The solution must perform real-time analytics on the logs, must support the replay of messages, and must persist the logs. Which AWS services should be used to meet these requirements? (Choose two.)

  1. Amazon Athena
  2. Amazon Kinesis Correct Answer
  3. Amazon SQS
  4. Amazon OpenSearch Service Correct Answer
  5. Amazon EMR

Community Votes

BD
100%

100% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Kinesis (Data Streams/Firehose) is the streaming ingestion layer that enables real-time analytics and replay (retention lets you re-read messages), while OpenSearch Service is the persistent store and search/analytics engine. Athena (A) is query-only over S3, not real-time streaming or replay; SQS (C) is a queue, not an analytics/search store; EMR (E) is heavyweight batch processing, overkill and not purpose-built for replay-plus-persist forensic logging.

Hundreds of Docker-on-EC2 apps need forensic logging with real-time analytics, message replay, and persistence. Amazon Kinesis ingests the log stream in real time, buffers it so messages can be replayed, and feeds downstream analytics. Amazon OpenSearch Service persists the logs and provides full-text search and dashboards for forensic discovery and processing. Together they satisfy all three requirements natively.

Picking Athena (A) for 'analytics'—Athena queries data at rest in S3 and is not a real-time streaming or replay mechanism. Picking SQS (C) thinking 'messaging'—SQS delivers once and does not persist or replay a log stream for analytics. EMR (E) is batch-oriented and far more operational overhead than a Kinesis-to-OpenSearch pipeline.

Community Discussion (3 comments)

lanjr01 👍 6
B & D Kinesis for forensic analysis and OpenSearch for discovery and processing https://docs.aws.amazon.com/opensearch-service/latest/developerguide/what-is.html
nRaiker 👍 2 Selected: BD
B,D - correct
Zek 👍 1
B,D - correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Amazon Kinesis ingests the forensic log stream in real time and retains it so messages can be replayed for re-analysis, meeting the real-time and replay requirements. Amazon OpenSearch Service persists the logs and provides full-text search, dashboards, and analytics for forensic discovery and processing, meeting the persistence requirement. The two services compose into a native end-to-end forensic pipeline.

Why the Other Options Are Wrong

A (Athena) only queries data already in S3 and offers no real-time streaming or replay. C (SQS) is a message queue for decoupling, not a log-analytics or replay store. E (EMR) is batch big-data processing with high operational overhead and is not purpose-built for live forensic log replay and persistence. B and D are the purpose-built pair.

Community Comment Notes

Community voted B,D (100). Commenters stated B (Kinesis) handles forensic analysis and D (OpenSearch) handles discovery and processing, linking the OpenSearch what-is doc. A, C, and E were not selected as they lack the streaming-plus-persistent-search combination.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide