I wanted to count the requests to one API endpoint in 15-minute windows, from the app’s logs in CloudWatch Logs Insights. Every variation I tried failed with:

unexpected symbol found (

The error pointed at the ( in sort bin(15m). Grouping with stats ... by bin(15m) is fine, but sort takes a field name, not a function call. Give the bin a name with as, and sort by that name:

filter @message like /\/api\/example\/search/
| stats count() as request_count by bin(15m) as block
| sort block

Put filter before anything that limits the results. My original query had limit 2000 first, which likely means it only counted within the newest 2,000 events.

For a chart, the Visualization tab draws a bin() query as a time series, so you don’t need to format the timestamps yourself.