1. 查询ip前10名日志数量
GET filebeat-*/_search
{
"size": 0,
"aggs": {
"top_ips": {
"terms": {
"field": "ip.keyword",
"size": 10,
"order": { "_count": "desc" }
}
}
}
}
2. 查询某一天的日志数量,例如2025年7月30日
GET filebeat-*/_search
{
"size": 0,
"query": {
"range": {
"@timestamp": {
"gte": "2025-07-30T00:00:00",
"lte": "2025-07-30T23:59:59",
"format": "yyyy-MM-dd'T'HH:mm:ss"
}
}
},
"aggs": {
"top_ips": {
"terms": {
"field": "ip.keyword",
"size": 10,
"order": { "_count": "desc" }
}
}
}
}
3. 查询某个单个ip某一天的日志量
GET filebeat-*/_count
{
"query": {
"bool": {
"must": [
{ "term": { "ip.keyword": "192.168.1.1" } },
{ "range": {
"@timestamp": {
"gte": "2025-07-30T00:00:00",
"lte": "2025-07-30T23:59:59",
"format": "yyyy-MM-dd'T'HH:mm:ss"
}
}}
]
}
}
}
1万+

被折叠的 条评论
为什么被折叠?



