# Availavility reports

**URL:** <https://discuss.elastic.co/t/availavility-reports/340659>\
**Category:** Elasticsearch\
**Tags:** eql-elastic-query-language\
**Created:** [August 11, 2023, 5:14pm UTC](https://discuss.elastic.co/t/availavility-reports/340659 "2023-08-11T17:14:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zenkovac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zenkovac/32/93645_2.png) [@zenkovac](https://discuss.elastic.co/u/zenkovac)\
**Post date:** [August 11, 2023, 5:14pm UTC](https://discuss.elastic.co/t/availavility-reports/340659/1 "2023-08-11T17:14:09Z")

</div>

hi, im looking for a way to have an availability report with maintenance windows exluded from the calculation.  
I have an index with availavility events that have basic status of 0 or 1, i can easily calculate the percentage of ok status over a period of time and calculate the percentage, I need to also take into account multiple maintenance windows that occur during a month, so events inbetween those windows wont afect the availavility report:

example of events:

■availavility events  
value=1/0 (1=ok,0=nok)  
timestamp=date an time of event  
type=status

■maintenance window events  
start\_date=date for start of window  
end\_datedate for end of window  
type=maintenance\_window

can anyone give me a hint?

regards

---

<div class="post-metadata">

**Author:** ![zenkovac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zenkovac/32/93645_2.png) [@zenkovac](https://discuss.elastic.co/u/zenkovac)\
**Post date:** [August 16, 2023, 12:47pm UTC](https://discuss.elastic.co/t/availavility-reports/340659/2 "2023-08-16T12:47:56Z")

</div>

anyone?

---

<div class="post-metadata">

**Author:** ![zenkovac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zenkovac/32/93645_2.png) [@zenkovac](https://discuss.elastic.co/u/zenkovac)\
**Post date:** [August 17, 2023, 3:16pm UTC](https://discuss.elastic.co/t/availavility-reports/340659/3 "2023-08-17T15:16:41Z")

</div>

is it possible to do something like this with painless?

---

<div class="post-metadata">

**Author:** ![zenkovac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zenkovac/32/93645_2.png) [@zenkovac](https://discuss.elastic.co/u/zenkovac)\
**Post date:** [August 21, 2023, 2:24pm UTC](https://discuss.elastic.co/t/availavility-reports/340659/4 "2023-08-21T14:24:47Z")

</div>

something like this:

{  
"query": {  
"bool": {  
"must\_not": {  
"bool": {  
"should": [  
{  
"range": {  
"timestamp": {  
"gte": "exceptions\_index.start\_time",  
"lte": "exceptions\_index.end\_time"  
}  
}  
}  
],  
"minimum\_should\_match": 1  
}  
}  
}  
}  
}

but its not wotking

Request error: date\_time\_parse\_exception, Failed to parse with all enclosed parsers in failed to parse date field [[RANGE exceptions\_index.start\_time TO exceptions\_index.end\_time]] with format [strict\_date\_optional\_time||epoch\_millis]

---

<div class="post-metadata">

**Author:** ![zenkovac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zenkovac/32/93645_2.png) [@zenkovac](https://discuss.elastic.co/u/zenkovac)\
**Post date:** [August 24, 2023, 7:03pm UTC](https://discuss.elastic.co/t/availavility-reports/340659/5 "2023-08-24T19:03:30Z")

</div>

solution was to enrich availability events because there is no such functionality like joins or sql "exists" in elk

in processor output do an update\_by\_query with the help of a painless script:

```
    http {
        url => "http://IP:9200/availavility_events/_update_by_query"
        headers => { "Authorization" => "Basic xxxxxx" }
        http_method => "post"
        format => "message"
        content_type => "application/json"
        message => '{"script":{"source":"ctx._source.maintenance_window = 1","lang":"painless"},"query":{"bool":{"filter":[{"range":{"time":{"gte":"%{start_time}","lte":"%{end_time}"}}}]}}}'
    }

```

The basic authentication field "xxxxxx" can be obtained with a base64 of user:password for the elastic api

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2023, 7:04pm UTC](https://discuss.elastic.co/t/availavility-reports/340659/6 "2023-09-21T19:04:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
