hi there!
could i have any idea for below situation.
i have these two logs
2018-03-19 09:51:04,500 (null) 19 WARN : mypage: TEST :: mnost2bj2pnqdzjajkvio20u :: Frontend Response : <FResponse><version>9.1</version><timeStamp>190318095104</timeStamp><RefID>1001</RefID></FResponse>
2018-03-19 09:51:04,500 (null) 19 WARN : mypage: TEST :: knost3bj2pnqdzbajkvio30u :: Backend Response : <BResponse><version>9.1</version><timeStamp>190318095104</timeStamp><RefID>1001</RefID></BResponse>
These two logs have same RefID
which is already done with grok pattern. I want to assume that if i found these two logs with same RefID
, i just want to count 1 time in kibana.
Is there any elasticsearch query to do like that?
I would appreciate for any advice.