Is it possible to do aggregations using Logstash


(Vilas Reddy Podduturi) #1

Can we do aggregations with logstash?

I want to read data from elasticsearch, say for last 10 mins and aggregate over a field and perform metrics over this aggregated data. Is it possible?

Thanks.


(Mark Walkom) #2

Perhaps this filter will do what you want https://www.elastic.co/guide/en/logstash/current/plugins-filters-collate.html

Otherwise, I'd suggest checking the others out.


(Vilas Reddy Podduturi) #3

Collate seems get me the data, but what I am looking for mainly is aggregation over a field.
Can Logstash do that?


(Fabien Baligand) #4

Maybe logstash-filter-aggregate could help.


(system) #5