# Howto which queries i could use?

**URL:** <https://discuss.elastic.co/t/howto-which-queries-i-could-use/886>\
**Category:** Kibana\
**Created:** [May 19, 2015, 8:38am UTC](https://discuss.elastic.co/t/howto-which-queries-i-could-use/886 "2015-05-19T08:38:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yzord](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yzord/32/44824_2.png) [@Yzord](https://discuss.elastic.co/u/Yzord)\
**Post date:** [May 19, 2015, 8:38am UTC](https://discuss.elastic.co/t/howto-which-queries-i-could-use/886/1 "2015-05-19T08:38:05Z")

</div>

Dear community,

Is there some howto available how and which queries i could use to simplify my search? I use a huge amount of log files and would like to simplify my searches on an easy base.

Any help?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 19, 2015, 8:53am UTC](https://discuss.elastic.co/t/howto-which-queries-i-could-use/886/2 "2015-05-19T08:53:50Z")

</div>

This question is too general. What do your logs look like? What fields have you extracted from them? What kind of searches do you want to make? We can tell you how to write queries that match the data you're interested in but we can't tell you what data you're interested in.

---

<div class="post-metadata">

**Author:** ![Yzord](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yzord/32/44824_2.png) [@Yzord](https://discuss.elastic.co/u/Yzord)\
**Post date:** [May 19, 2015, 1:31pm UTC](https://discuss.elastic.co/t/howto-which-queries-i-could-use/886/3 "2015-05-19T13:31:15Z")

</div>

Thank you for your reply. How can i tell you how my logs look like? I have centralised postfix, dhcp and secure logs from several servers and have no specific fields extracted from them...just the complete log files are pushed to my ELK server.

I have named all logs according to their server name like "server1-maillog" and "server2-dhcpd" etc. etc. in the logstash-forwarder config file.

I would like to know the query of the following. I want to know which mac address use IP X.X.X.X at a specific time and i want to search in the "server2-dhcpd" log file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 20, 2015, 6:02am UTC](https://discuss.elastic.co/t/howto-which-queries-i-could-use/886/4 "2015-05-20T06:02:58Z")

</div>

> How can i tell you how my logs look like?

Well, you for example could copy/paste a message's JSON representation from Kibana.

> I want to know which mac address use IP X.X.X.X at a specific time and i want to search in the "server2-dhcpd" log file.

You'll have to parse those logs with a [grok filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) in Logstash so that you extract at least the IP address into a separate field. Once that's done a query similar to `clientip:X.X.X.X AND type:dhcpd` (depending on what names you give the fields) will find the matching entries.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:19pm UTC](https://discuss.elastic.co/t/howto-which-queries-i-could-use/886/5 "2017-07-06T14:19:17Z")

</div>


