1、聚合某个索引中HTTP状态码为5XX的域名。
GET logstash-access-2018.12.28/_search
{
"query": {
"match": {
"status": "500 502 503 504"
}
},
"aggs": {
"status_5xx": {
"terms": {
"field": "http_host.keyword",
"size": 10
}
}
}
,
"size": 0
}
2. 某时段的站点5XX聚合统计(注意时区问题,东八区和标准时间差距8小时)
GET logstash-f1-hq-access-2019.01.11/_search
{
"size": 0,
"query": {
"bool": {
"must": [
{
"match": {"status": "500 502 503 504"}
},
{
"range": {
"@timestamp": {
"gte": "2019-01-11T01:00:00.000000000+00:00",
"lte": "2019-01-11T01:00:01.000000000+00:00"
}
}
}
]
}
},
"aggs": {
"hq_5xx_aggs": {
"terms": {
"field": "http_host.keyword",
"size": 10
}
}
}
}