Skip to content

Split large result sets into time-chunked queries #5

Description

@bcelenza

Occasionally you need to write a query and get all the results across a long time span (say a month). Performing a single search for that period may return a truncated list of results capped at the maximum returned by CloudWatch (default: 1000, up to 10000 with limit).

It would be great to at least specify a flag that would split the query up into time chunks that could allow combination of all results in the full period.

So a command like:

cwq --log-group MyLogGroup --start 1y --interval 1d '....'

Would search a log group for an entire year, but in successive (or potentially parallel) one day chunks, combining all the results at the end.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions