we have monitoring the servers with different tools and get the events when any server is down from all monitoring tools. we are inserting all these event as records doc type in elastic-search. we need to write query to in such way that
get first inserted record from the same host(I can apply aggregation on server filed) and with in last 10min time. if we get the first inserted record then we can suppress the later inserted events in last 10 min on same device from different sources.
can you please help me on how to get the first inserted record on the same host in last 10 min of records?