Question 134:
Your customer is willing to consolidate their log streams, access logs, application logs, security logs, etc. in one single system. Once consolidated, the customer wants to analyze these logs in real-time based on heuristics. From time to time, the customer needs to validate heuristics, which requires going back to data samples extracted from the last 12 hours? What is the best approach to meet your customer’s requirements?
Answer options:
A.Send all the log events to Amazon SQS. Setup an Auto Scaling group of EC2 servers to consume the logs and apply the heuristics. B.Send all the log events to Amazon Kinesis. Develop a client process to apply heuristics to the logs. C.Configure Amazon Cloud Trail to receive custom logs and use EMR to apply heuristics to the logs. D.Setup Auto Scaling group of EC2 Syslog servers and store the logs S3 use EMR to apply heuristics on the logs.