Re: Multi Field Aggregation

2014-10-19 Thread Artur Martins
I heard that it could be done with a fingerprint, but I don't know how to do this. It's in logstash.conf Have a look: Fingerprint the 3-tuple of source address, destination address, destination port if [SourceAddress] and [DestinationAddress] { fingerprint { concatenate_sources = true

Re: Multi Field Aggregation

2014-10-19 Thread Artur Martins
-defined in that way. Al On 19 October 2014 16:48, Artur Martins artu...@gmail.com javascript: wrote: I heard that it could be done with a fingerprint, but I don't know how to do this. It's in logstash.conf Have a look: Fingerprint the 3-tuple of source address, destination address

How to count tuples of 3 variables, sorted

2014-10-17 Thread Artur Martins
Greetings community, I'm new to elasticsearch, so first of all sorry for my questions being so basic. I developed a flow collector which dumps flows to my elasticsearch server. Right now i use Kibana to perform the Top 10 destination and Top 10 source IPs filters, and such. But the query I'm

Re: Multi Field Aggregation

2014-10-17 Thread Artur Martins
Hello, I'm having the exact same problem. Have you managed to find a solution? My thread is here: LINK https://groups.google.com/forum/?fromgroups#!topic/elasticsearch/Oum03VSBzHQ Thanks On Thursday, October 16, 2014 1:57:35 PM UTC+1, Alastair James wrote: Hi there. I am trying to create

Re: [ANN] Elasticsearch CSV plugin for formatting search responses as CSV

2014-10-17 Thread Artur Martins
This is priceless. Thank you. On Wednesday, July 16, 2014 12:23:11 AM UTC+1, Jörg Prante wrote: Hi, I wrote a little plugin for formatting search responses as CSV (comma separated values) This format is useful for extracting some (or all) fields from ES JSON and wrap it into a tabular