时间格式化
"format": "yyyy-MM-dd HH:mm:ss || yyyy-MM-dd",
GET log-lingxi_backend*/_search
{
"aggs": {
"aggs_num": {
"adjacency_matrix": {
"filters": {
"First_five_minutes": {
"bool": {
"must": [
{
"range": {
"timestamp": {
"gte": "now-1d"
}
}
}
]
}
},
"First_ten_minutes": {
"bool": {
"must": [
{
"range": {
"timestamp": {
"gte": "now-5m"
}
}
}
]
}
}
}
},
"aggs": {
"aggs_level": {
"terms": {
"field": "levelname.keyword"
}
}
}
}
},
"size": 0,
"_source": ["timestamp","levelname"]
}
GET log-lingxi_back*/_mapping
GET log-lingxi_backend*/_search
{
"query": {
"prefix": {
"msg.keyword": {
"value": "用"
}
}
},
"_source": ["msg"]
}
GET log-lingxi-merchant-api*/_search
{
"aggs": {
"time_range": {
"range": {
"field": "timestamp",
"ranges": [
{
"from": "now-60d",
"key": "now-60d"
},
{
"from": "now-30m",
"key": "now-30m"
},
{
"from": "now-15m",
"key": "now-15m"
},
{
"from": "now-5m",
"key": "now-5m"
}
]
},
"aggs": {
"aggs_level": {
"terms": {
"field": "levelname.keyword"
}
}
}
}
},
"size": 0
}
GET log-lingxi-merchant-api*/_search
{
"aggs": {
"s_type": {
"terms": {
"field": "type.keyword"
},
"aggs": {
"time_range": {
"range": {
"field": "timestamp",
"ranges": [
{
"from": "now-60d",
"key": "now-60d"
},
{
"from": "now-30m",
"key": "now-30m"
},
{
"from": "now-15m",
"key": "now-15m"
},
{
"from": "now-5m",
"key": "now-5m"
}
]
},
"aggs": {
"aggs_level": {
"terms": {
"field": "levelname.keyword"
}
}
}
}
}
}
},
"size": 0
}
GET log-lingxi_backend*/_search
{
"_source": [
"name",
"msg",
"type",
"levelname",
"message",
"log",
"timestamp",
"sql"
],
"from": 0,
"query": {
"bool": {
"must": [
{"range": {
"timestamp":{
"gt": "2021-12-26T11:24:90"
}
}}
]
}
},
"size": 2,
"sort": {
"timestamp": {
"order": "desc"
}
},
"track_total_hits": "true"
}
GET log-lingxi-merchant-api*/_search
{
"_source": [
"name",
"msg",
"type",
"levelname",
"message",
"log",
"timestamp",
"sql"
],
"from": 0,
"query": {
"bool": {
"must": [
{"range": {
"timestamp":{
"gt": "2021-12-27T05:29:37.531Z"
}
}}
]
}
},
"sort": {
"timestamp": {
"order": "desc"
}
},
"track_total_hits": "true"
}
GET log-lingxi-merchant-api*/_search
{
"query": {
"bool": {
"must": [
{
"range": {
"timestamp": {
"gt": "2021-12-27T05:29:37.531Z"
}
}
},
{"term": {
"type": {
"value": "system"
}
}}
]
}
},
"track_total_hits": "true",
"aggs": {
"request_histogram": {
"date_histogram": {
"field": "timestamp",
"fixed_interval": "5m",
"format": "yyyy-MM-dd HH:mm:SS"
}
}
},
"size": 0
}
GET log-lingxi-merchant-api-2021.12.20/_search
{
"query": {
"bool": {
"must": [
{
"term": {
"type": "service"
}
},
{
"range": {
"timestamp":{
"gte": "2021-11-25 20:10:10",
"lt": "now",
"format": "yyyy-MM-dd HH:mm:SS||yyyy-MM-dd"
}
}
}
]
}
},
"aggs": {
"project": {
"terms": {
"field": "project.keyword",
"order": {
"total_record": "desc"
}
},
"aggs": {
"total_record": {
"value_count": {
"field": "levelname.keyword"
}
},
"error": {
"filter": {
"term": {
"levelname.keyword": "ERROR"
}
}
},
"level_percentage": {
"bucket_script": {
"buckets_path": {
"E": "error > _count",
"T": "total_record"
},
"format": "#.##",
"script": "params.E /params.T * 100"
}
},
"rate_bucket_sort": {
"bucket_sort": {
"sort": [
{
"level_percentage.value": {
"order": "desc"
}
}
]
}
}
}
}
},
"size": 0
}
GET log-*/_search
{
"query": {
"bool": {
"must": [
{
"term": {
"type": "service"
}
},
{
"range": {
"timestamp": {
"gte": "2021-12-23",
"lt": "now",
"format": "yyyy-MM-dd HH:mm:SS||yyyy-MM-dd"
}
}
}
]
}
},
"aggs": {
"error": {
"filter": {
"term": {
"levelname.keyword": "ERROR"
}
},
"aggs": {
"request_histogram": {
"date_histogram": {
"field": "timestamp",
"fixed_interval": "2d",
"format": "yyyy-MM-dd HH:mm:SS"
}
}
}
}
,
"total_record": {
"date_histogram": {
"field": "timestamp",
"fixed_interval": "2d",
"format": "yyyy-MM-dd HH:mm:SS"
}
}
},
"track_total_hits": "true",
"size": 0
}
GET log-lingxi-merchant-api*/_search
{
"query": {
"bool": {
"must": [
{
"term": {
"type": "service"
}
},
{
"range": {
"timestamp": {
"gte": "2021-12-23",
"lt": "now",
"format": "yyyy-MM-dd HH:mm:SS||yyyy-MM-dd"
}
}
}
]
}
},
"aggs": {
"request_histogram": {
"date_histogram": {
"field": "timestamp",
"fixed_interval": "2d",
"format": "yyyy-MM-dd HH:mm:SS"
},
"aggs": {
"error": {
"filter": {
"term": {
"levelname.keyword": "ERROR"
}
}
},
"level_percentage": {
"bucket_script": {
"buckets_path": {
"E": "error > _count",
"T": "_count"
},
"format": "#.##",
"script": "(1-params.E /params.T) * 100"
}
}
}
}
}
,
"track_total_hits": "true",
"size": 0
}
网友评论