We have tomcat access logs in one index called "access" (with fields like timeTaken and bytesSent) and we'd like to have this data aggregated into another index "stats" with, for example, the average timeTaken for certain pages or the sum of all 500 errors. We plan to have only daily granularity in the "stats" index.
We would like some tips and pointers on how to achieve this.
- Is it possible within ELK w/o coding ruby or making an external script to query and push the data?
- How does one pull the aggregated SUM and AVG data from ES?
- If we wanted the data only daily, could we schedule such runs within ELK?
Thanks in advance!