0
我需要以书面看守输入查询ElasticSearch(V5.3)的帮助。我的要求是在apache状态码变为500或更多时触发警报。ElasticSearch看守过滤范围查询
Index name: Apache-access-log Field name: status_code Kibana Discover query: status_code: [500 TO 600] Time period: Last 15 minutes.
这里是我曾经用过的看守输入查询,但预期它并没有奏效。
{
"search": {
"request": {
"index": [
"Apache-access-log"
],
"body": {
"query": {
"filtered": {
"query": {
"query_string": {
"query": "status_code: 500",
}
},
"filter": {
"range": {
"@timestamp": {
"gte": "now-15m",
"lte": "now"
}
}
}
}
}
}
}
}
}