# Finding a sequence of events

**URL:** <https://discuss.elastic.co/t/finding-a-sequence-of-events/220269>\
**Category:** Elasticsearch\
**Created:** [February 20, 2020, 9:03pm UTC](https://discuss.elastic.co/t/finding-a-sequence-of-events/220269 "2020-02-20T21:03:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeremy\_A](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremy_a/32/42598_2.png) [@Jeremy\_A](https://discuss.elastic.co/u/Jeremy_A)\
**Post date:** [February 20, 2020, 9:03pm UTC](https://discuss.elastic.co/t/finding-a-sequence-of-events/220269/1 "2020-02-20T21:03:01Z")

</div>

Hi, I've seen some info online about this but much of it was a few years old so I was wondering what the best solution would be to this problem of finding a sequence of events from discreet logs.

We have an index with alert codes that come from machines, and each alert code comes in as a new document. We want to create a report that identifies when a certain pattern of alerts comes in.

For example, if you have the following documents:

```
{
  "machine_id" : "A1",
  "alert_code": "1"
}
{
  "machine_id" : "B1",
  "alert_code": "3"
}
{
  "machine_id" : "B1",
  "alert_code": "1"
}
{
  "machine_id" : "A1",
  "alert_code": "5"
}
{
  "machine_id" : "A1",
  "alert_code": "1"
}
{
  "machine_id" : "A1",
  "alert_code": "2"
}
{
  "machine_id" : "A1",
  "alert_code": "3"
}

```

Then i want to be able to search for instances where the same machine issued alerts 1-2-3 in that order, but we don't care if it issues 1-3-2 or 1-4-6 for example. Or if there was a 1-2-3 but not all from the same machine for that matter).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 20, 2020, 9:12pm UTC](https://discuss.elastic.co/t/finding-a-sequence-of-events/220269/2 "2020-02-20T21:12:33Z")

</div>

Is there a timestamp in each doc?

---

<div class="post-metadata">

**Author:** ![Jeremy\_A](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremy_a/32/42598_2.png) [@Jeremy\_A](https://discuss.elastic.co/u/Jeremy_A)\
**Post date:** [February 20, 2020, 9:35pm UTC](https://discuss.elastic.co/t/finding-a-sequence-of-events/220269/3 "2020-02-20T21:35:52Z")

</div>

Yes, each document also has a @timestamp and sequence\_number associated with it.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 20, 2020, 9:42pm UTC](https://discuss.elastic.co/t/finding-a-sequence-of-events/220269/4 "2020-02-20T21:42:25Z")

</div>

Then you can aggregate by host, sorted by timestamp.

You could probably also write a watch script that finds that particular ordering, but I am not super sure if you can do that in another way.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2020, 9:42pm UTC](https://discuss.elastic.co/t/finding-a-sequence-of-events/220269/5 "2020-03-19T21:42:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
