Use Kinesis for real-time forensic log streaming and OpenSearch Service for persistent log analytics
A company needs a forensic-logging solution for hundreds of applications running in Docker on Amazon EC2. The solution must perform real-time analytics on the logs, must support the replay of messages, and must persist the logs. Which AWS services should be used to meet these requirements? (Choose two.)
Community Votes
100% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Kinesis (Data Streams/Firehose) is the streaming ingestion layer that enables real-time analytics and replay (retention lets you re-read messages), while OpenSearch Service is the persistent store and search/analytics engine. Athena (A) is query-only over S3, not real-time streaming or replay; SQS (C) is a queue, not an analytics/search store; EMR (E) is heavyweight batch processing, overkill and not purpose-built for replay-plus-persist forensic logging.
Hundreds of Docker-on-EC2 apps need forensic logging with real-time analytics, message replay, and persistence. Amazon Kinesis ingests the log stream in real time, buffers it so messages can be replayed, and feeds downstream analytics. Amazon OpenSearch Service persists the logs and provides full-text search and dashboards for forensic discovery and processing. Together they satisfy all three requirements natively.
Picking Athena (A) for 'analytics'—Athena queries data at rest in S3 and is not a real-time streaming or replay mechanism. Picking SQS (C) thinking 'messaging'—SQS delivers once and does not persist or replay a log stream for analytics. EMR (E) is batch-oriented and far more operational overhead than a Kinesis-to-OpenSearch pipeline.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.