# How to identify/display set of sequence data In the log file

**URL:** <https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043>\
**Category:** Logstash\
**Created:** [February 15, 2018, 5:40pm UTC](https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043 "2018-02-15T17:40:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajkamalkool6](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@rajkamalkool6](https://discuss.elastic.co/u/rajkamalkool6)\
**Post date:** [February 15, 2018, 5:40pm UTC](https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043/1 "2018-02-15T17:40:18Z")

</div>

I got one different use case from my client which I need to identify a set of log data which got recorded in sequence at any line in the log file and they want to view the identified sequence in Kibana and its related count. I am wondering whether it is possible to achieve it in Logstash filter or in Kibana query.

Below is my log file.

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/9/29751041aad58038bbb023e2476640b812006603.png)

for example I have to get the count of the below sequence appeared anywhere in the log file.

1. LS=Select  
LS=Symmetry  
LS=Select  
LS=Select  
LS=Mirror  
LS=Select

2. LS=Select  
LS=Modify  
LS=\* (which can be anything)  
LS=Select  
LS \<\> Select (This needs to be a command)

Please advice whether its possible to achieve.

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [February 15, 2018, 5:55pm UTC](https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043/2 "2018-02-15T17:55:41Z")

</div>

I think you would need to do that in a logstash filter. The sequence of the individual log entries get lost during the ingestion of individual lines. I would suggest asking this question in the logstash forum.

---

<div class="post-metadata">

**Author:** ![rajkamalkool6](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@rajkamalkool6](https://discuss.elastic.co/u/rajkamalkool6)\
**Post date:** [February 15, 2018, 6:13pm UTC](https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043/3 "2018-02-15T18:13:50Z")

</div>

I updated the question topic to Logstash. Thank you for showing the path.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 16, 2018, 7:49am UTC](https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043/4 "2018-02-16T07:49:32Z")

</div>

At least if you use Filebeat it'll add a field to each event with the file offset of the line in question.

---

<div class="post-metadata">

**Author:** ![rajkamalkool6](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@rajkamalkool6](https://discuss.elastic.co/u/rajkamalkool6)\
**Post date:** [February 16, 2018, 3:55pm UTC](https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043/5 "2018-02-16T15:55:52Z")

</div>

@magnusbaeck. Sorry I couldn't understand it properly can you please explain it in detail.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 19, 2018, 7:12am UTC](https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043/6 "2018-02-19T07:12:38Z")

</div>

If you use Filebeat instead of Logstash for reading the files, each event will contain a field that indicates the position in the file of that line.

If this still isn't clear you'll have to explain what part you don't understand.

---

<div class="post-metadata">

**Author:** ![rajkamalkool6](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@rajkamalkool6](https://discuss.elastic.co/u/rajkamalkool6)\
**Post date:** [February 21, 2018, 4:37pm UTC](https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043/7 "2018-02-21T16:37:21Z")

</div>

I am using filebeat but how can i achieve the sequence search using position of the file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 21, 2018, 6:08pm UTC](https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043/8 "2018-02-21T18:08:41Z")

</div>

Ideally you'd just use the file offset field as the secondary sort field, but I don't think Kibana supports that. You could perhaps experiment with adding parts of the offset as the millisecond part of the timestamp.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2018, 6:09pm UTC](https://discuss.elastic.co/t/how-to-identify-display-set-of-sequence-data-in-the-log-file/120043/9 "2018-03-21T18:09:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
