# Finding most frequently accessed URI-paths / Transactions using Logstash

**URL:** <https://discuss.elastic.co/t/finding-most-frequently-accessed-uri-paths-transactions-using-logstash/92644>\
**Category:** Logstash\
**Created:** [July 11, 2017, 12:52pm UTC](https://discuss.elastic.co/t/finding-most-frequently-accessed-uri-paths-transactions-using-logstash/92644 "2017-07-11T12:52:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![anisen](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@anisen](https://discuss.elastic.co/u/anisen)\
**Post date:** [July 11, 2017, 12:52pm UTC](https://discuss.elastic.co/t/finding-most-frequently-accessed-uri-paths-transactions-using-logstash/92644/1 "2017-07-11T12:52:17Z")

</div>

Hi,

My log file looks like this:

2015-06-12:00:08:54 100.220.144.1 GET /site/path1.aspx 200  
2015-06-12:00:08:55 100.220.144.1 GET /site/path2.aspx 200  
2015-06-12:00:08:56 100.220.144.1 GET /site/path3.aspx 200  
2015-06-12:00:08:56 100.220.144.1 GET /site/path4.aspx 200  
2015-06-12:00:08:57 100.220.144.1 GET /site/path1.aspx 200  
2015-06-12:00:08:57 100.220.144.1 GET /site/path5.aspx 200  
2015-06-12:00:08:58 100.220.144.1 GET /site/path1.aspx 200  
2015-06-12:00:08:59 100.220.144.1 GET /site/path2.aspx 200  
2015-06-12:00:08:59 100.220.144.1 GET /site/path3.aspx 200  
2015-06-12:00:08:59 100.220.144.1 GET /site/path5.aspx 200  
2015-06-12:00:08:59 100.220.144.1 GET /site/path4.aspx 200

Now, in the log, the most frequently accessed transaction or URL-path is:  
(/site/path1.aspx --\>/site/path2.aspx --\> /site/path3.aspx)

Is there any way to detect this using Logstash? Please suggest.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 12, 2017, 7:08pm UTC](https://discuss.elastic.co/t/finding-most-frequently-accessed-uri-paths-transactions-using-logstash/92644/2 "2017-07-12T19:08:42Z")

</div>

This is what you'd normally use Elasticsearch for. What's the point of making Logstash perform this ranking? Given the example input above, what event(s) would you expect Logstash to produce?

---

<div class="post-metadata">

**Author:** ![anisen](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@anisen](https://discuss.elastic.co/u/anisen)\
**Post date:** [July 14, 2017, 6:04am UTC](https://discuss.elastic.co/t/finding-most-frequently-accessed-uri-paths-transactions-using-logstash/92644/3 "2017-07-14T06:04:48Z")

</div>

Hi @magnusbaeck . Thanks for the response.

I am expecting a new column to be created named "userpath" which will have all the userpaths(collection of URIs in sequence between a entry URI(say, Login.jsp) and exit URI(say, LogOut.jsp)).

I tried the following code:

if [uri] == "Login.jsp" {  
aggregate {  
task\_id =\> "%{clientip}"  
code =\> "map['userpath'] = event.get('uri') ; map['userpath'] += ' --- ' "  
map\_action =\> "create"  
}  
}  
else {  
if [uri] != "Login.jsp" and [uri] != "Logout.jsp"{  
aggregate {  
task\_id =\> "%{clientip}"  
code =\> "map['userpath'] += event.get('uri') ; map['userpath'] += ' --- ' "  
map\_action =\> "update"  
}  
}  
if [uri] == "Logout.jsp"{  
aggregate {  
task\_id =\> "%{clientip}"  
code =\> "map['userpath'] += event.get('uri') ; event.set('userpath', map['userpath'])"  
map\_action =\> "update"  
end\_of\_task =\> true  
push\_previous\_map\_as\_event =\> true  
}  
}  
}

I am getting a partially correct result.

But, want to consider few more scenarios to get a more accurate result,like:  
1 . If the user logs-In, but then doesn't click on LogOut, and again comes to Login Page. So, (Login.jsp --- /somePage1.jsp --- /somePage2.jsp --- Login.jsp ) should be the path.

2 . If the user logs in and timeout occurs(say, timeout = 15 mins). So in this case, from (Login.jsp --- whatever he has clicked till timeout) should be the userpath.  
etc..

Please suggest.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 14, 2017, 6:41am UTC](https://discuss.elastic.co/t/finding-most-frequently-accessed-uri-paths-transactions-using-logstash/92644/4 "2017-07-14T06:41:31Z")

</div>

I think this sounds like a good use-case for an [entity-centric index](https://www.elastic.co/videos/entity-centric-indexing-mark-harwood).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2017, 6:42am UTC](https://discuss.elastic.co/t/finding-most-frequently-accessed-uri-paths-transactions-using-logstash/92644/5 "2017-08-11T06:42:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
