Filebeat: input: awscloudwatch (expression pattern for log_group)

I have many log_groups in clodwatch ~ 400.
But I need parse only 77 from this long list.

Can I grab events from log group use some pattern?
For example:

log_group_arn: arn:aws:logs:us-east-1:0000000000:log-group:/development/application/*

or
log_group_name: /development/application/*

I tried this, but every time got an error:

getLogEventsFromCloudWatch failed: InvalidParameterException: 1 validation error detected: Value ':/development/application/*' at 'logGroupName' failed to satisfy constraint: Member must satisfy regular expression pattern: [\.\-_/#A-Za-z0-9]+

Wich pattern I should use?

Maybe I miss some options...

Filebeat input method awscloudwatch currently does not support discovery mode for log_group.
see more: https://github.com/elastic/beats/issues/21528

1 Like

Yep sorry I missed this discuss issue earlier.