A developer suspects a Lambda function is timing out and wants the 20 most recent invocations whose logs contain "Task timed out", newest first. Which CloudWatch Logs Insights query achieves this?
Choose one.
Logs Insights queries chain commands with pipes: filter narrows events, sort orders them, and limit caps how many return. The system fields @timestamp and @message are always available, and sort @timestamp desc is how "most recent first" is expressed.
Option b is the canonical shape for "the latest N events matching a pattern": filter to the timeout text, sort descending by timestamp, limit to 20. Option a sorts ascending and therefore returns the oldest matches. Option c produces bucketed counts, not events, and applies its filter in the wrong position. Option d uses parse, which extracts fields rather than filtering, so non-matching events still flow through.
- Choose the function's log group and a time range covering the incident.
- filter @message like /Task timed out/ to keep only the relevant events.
- sort @timestamp desc so the newest occurrences come first.
- limit 20 to cap the result set at the number you need.
Exam tip: filter + sort desc + limit is the Logs Insights pattern for "the most recent N matching events".
Root Cause Analysis on AWS: Reading Logs, Metrics, and Error Codes — the lesson that teaches this.