# \[Kibana\] group by request?

**URL:** <https://discuss.elastic.co/t/kibana-group-by-request/21271>\
**Category:** Elasticsearch\
**Created:** [December 16, 2014, 9:03am UTC](https://discuss.elastic.co/t/kibana-group-by-request/21271 "2014-12-16T09:03:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![stephanos](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@stephanos](https://discuss.elastic.co/u/stephanos)\
**Post date:** [December 16, 2014, 9:03am UTC](https://discuss.elastic.co/t/kibana-group-by-request/21271/1 "2014-12-16T09:03:06Z")

</div>

Hey there,

we are using Google App Engine to host our SaaS app. Google offers a nice  
log browser but it is way too sloooow. So one of my colleagues suggested we  
pipe our logs to logstash and make them accessible via Kibana. So far so  
good, we managed to set everything up.

But when Kibana was shown to the other team members they weren't really  
excited. It was much faster, yes. It allowed to make better queries, yes.  
BUT it broke the pattern they knew from the Google App Engine log browser:

```
/some-request
    log message 1
    log message 2
/another-request
    log message 3
/yet-another-request
    log message 4

```

While Kibana works like this:

```
log message 1 /some-request
log message 2 /some-request
log message 3 /another-request
log message 4 /yet-another-request

```

So basically App Engine groups log messages by request. To get my team on  
board, can we make Kibana do the same?

Stephan

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/aacdaf38-c614-4dbc-b4d8-a81b832dbc31%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/aacdaf38-c614-4dbc-b4d8-a81b832dbc31%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 22, 2014, 6:38am UTC](https://discuss.elastic.co/t/kibana-group-by-request/21271/2 "2014-12-22T06:38:17Z")

</div>

On Tuesday, December 16, 2014 at 10:03 CET,  
stephanos [stephan.behnke@gmail.com](mailto:stephan.behnke@gmail.com) wrote:

> we are using Google App Engine to host our SaaS app. Google offers a  
> nice log browser but it is way too sloooow. So one of my colleagues  
> suggested we pipe our logs to logstash and make them accessible via  
> Kibana. So far so good, we managed to set everything up.  
> But when Kibana was shown to the other team members they weren't  
> really excited. It was much faster, yes. It allowed to make better  
> queries, yes. BUT it broke the pattern they knew from the Google App  
> Engine log browser:  
> /some-request  
> log message 1  
> log message 2  
> /another-request  
> log message 3  
> /yet-another-request  
> log message 4  
> While Kibana works like this:  
> log message 1 /some-request  
> log message 2 /some-request  
> log message 3 /another-request  
> log message 4 /yet-another-request  
> So basically App Engine groups log messages by request. To get my  
> team on board, can we make Kibana do the same?

Not out of the box, no. Kibana doesn't have any such contextual  
understanding of messages and currently can't be configured as  
such either.

--  
Magnus Bäck | Software Engineer, Development Tools  
[magnus.back@sonymobile.com](mailto:magnus.back@sonymobile.com) | Sony Mobile Communications

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/20141222063817.GB11963%40seldlx20533.corpusers.net](https://groups.google.com/d/msgid/elasticsearch/20141222063817.GB11963%40seldlx20533.corpusers.net).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![stephanos](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@stephanos](https://discuss.elastic.co/u/stephanos)\
**Post date:** [December 22, 2014, 8:58am UTC](https://discuss.elastic.co/t/kibana-group-by-request/21271/3 "2014-12-22T08:58:57Z")

</div>

Thanks for the answer!  
I think wasn't clear enough: all our log messages already have a requestID.  
So if there _was_ a grouping feature we'd apply it to that field.

I'm just wondering, how do you troubleshoot a issue of a user? When we see  
a problem we look at all requests of that user in the GAE log viewer. Then  
you quickly see requests that have non-200 status codes. Then we drill into  
a request and see all logs of _that_ request chronologically. While in  
Kibana I can also look at all logs from a user ordered by time, but it's  
not always completely clear which request log messages belong to. It's more  
like one big stream.

My point is, you should really try out the Google App Engine log viewer -  
then you would know what you are missing! 🙂

Stephan

On Monday, December 22, 2014 7:38:26 AM UTC+1, Magnus Bäck wrote:

> On Tuesday, December 16, 2014 at 10:03 CET,  
> stephanos \<[stephan...@gmail.com](mailto:stephan...@gmail.com) \<javascript:\>\> wrote:
> 
> > we are using Google App Engine to host our SaaS app. Google offers a  
> > nice log browser but it is way too sloooow. So one of my colleagues  
> > suggested we pipe our logs to logstash and make them accessible via  
> > Kibana. So far so good, we managed to set everything up.  
> > But when Kibana was shown to the other team members they weren't  
> > really excited. It was much faster, yes. It allowed to make better  
> > queries, yes. BUT it broke the pattern they knew from the Google App  
> > Engine log browser:  
> > /some-request  
> > log message 1  
> > log message 2  
> > /another-request  
> > log message 3  
> > /yet-another-request  
> > log message 4  
> > While Kibana works like this:  
> > log message 1 /some-request  
> > log message 2 /some-request  
> > log message 3 /another-request  
> > log message 4 /yet-another-request  
> > So basically App Engine groups log messages by request. To get my  
> > team on board, can we make Kibana do the same?
> 
> Not out of the box, no. Kibana doesn't have any such contextual  
> understanding of messages and currently can't be configured as  
> such either.
> 
> --  
> Magnus Bäck | Software Engineer, Development Tools  
> [magnu...@sonymobile.com](mailto:magnu...@sonymobile.com) \<javascript:\> | Sony Mobile Communications

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/8cbd90e7-5e12-4cd7-90d6-35f49dc44e1d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/8cbd90e7-5e12-4cd7-90d6-35f49dc44e1d%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Arie](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@Arie](https://discuss.elastic.co/u/Arie)\
**Post date:** [December 22, 2014, 1:42pm UTC](https://discuss.elastic.co/t/kibana-group-by-request/21271/4 "2014-12-22T13:42:13Z")

</div>

Hi,

Maybe graylog2 can interst you as a solution to store your data in ES, and  
therefore you have better searching of your data.  
Especially data coming form a webserver as I understand. You then can stil  
search or display data with Kibana.

A.

Op maandag 22 december 2014 09:58:57 UTC+1 schreef stephanos:

> Thanks for the answer!  
> I think wasn't clear enough: all our log messages already have a  
> requestID. So if there _was_ a grouping feature we'd apply it to that  
> field.
> 
> I'm just wondering, how do you troubleshoot a issue of a user? When we see  
> a problem we look at all requests of that user in the GAE log viewer. Then  
> you quickly see requests that have non-200 status codes. Then we drill into  
> a request and see all logs of _that_ request chronologically. While in  
> Kibana I can also look at all logs from a user ordered by time, but it's  
> not always completely clear which request log messages belong to. It's more  
> like one big stream.
> 
> My point is, you should really try out the Google App Engine log viewer -  
> then you would know what you are missing! 🙂
> 
> Stephan
> 
> On Monday, December 22, 2014 7:38:26 AM UTC+1, Magnus Bäck wrote:
> 
> > On Tuesday, December 16, 2014 at 10:03 CET,  
> > stephanos [stephan...@gmail.com](mailto:stephan...@gmail.com) wrote:
> > 
> > > we are using Google App Engine to host our SaaS app. Google offers a  
> > > nice log browser but it is way too sloooow. So one of my colleagues  
> > > suggested we pipe our logs to logstash and make them accessible via  
> > > Kibana. So far so good, we managed to set everything up.  
> > > But when Kibana was shown to the other team members they weren't  
> > > really excited. It was much faster, yes. It allowed to make better  
> > > queries, yes. BUT it broke the pattern they knew from the Google App  
> > > Engine log browser:  
> > > /some-request  
> > > log message 1  
> > > log message 2  
> > > /another-request  
> > > log message 3  
> > > /yet-another-request  
> > > log message 4  
> > > While Kibana works like this:  
> > > log message 1 /some-request  
> > > log message 2 /some-request  
> > > log message 3 /another-request  
> > > log message 4 /yet-another-request  
> > > So basically App Engine groups log messages by request. To get my  
> > > team on board, can we make Kibana do the same?
> > 
> > Not out of the box, no. Kibana doesn't have any such contextual  
> > understanding of messages and currently can't be configured as  
> > such either.
> > 
> > --  
> > Magnus Bäck | Software Engineer, Development Tools  
> > [magnu...@sonymobile.com](mailto:magnu...@sonymobile.com) | Sony Mobile Communications

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/cfe61a16-63ad-46a3-9747-2d4a73815627%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/cfe61a16-63ad-46a3-9747-2d4a73815627%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![sonnend](https://avatars.discourse-cdn.com/v4/letter/s/8baadc/32.png) [@sonnend](https://discuss.elastic.co/u/sonnend)\
**Post date:** [December 23, 2014, 7:40pm UTC](https://discuss.elastic.co/t/kibana-group-by-request/21271/5 "2014-12-23T19:40:05Z")

</div>

I'm not sure whether I understand your issue in full depth but you can use  
nested aggregations to have hierarchical grouping in Kibana 4. Maybe this  
solves your issue?

Am Montag, 22. Dezember 2014 09:58:57 UTC+1 schrieb stephanos:

> Thanks for the answer!  
> I think wasn't clear enough: all our log messages already have a  
> requestID. So if there _was_ a grouping feature we'd apply it to that  
> field.
> 
> I'm just wondering, how do you troubleshoot a issue of a user? When we see  
> a problem we look at all requests of that user in the GAE log viewer. Then  
> you quickly see requests that have non-200 status codes. Then we drill into  
> a request and see all logs of _that_ request chronologically. While in  
> Kibana I can also look at all logs from a user ordered by time, but it's  
> not always completely clear which request log messages belong to. It's more  
> like one big stream.
> 
> My point is, you should really try out the Google App Engine log viewer -  
> then you would know what you are missing! 🙂
> 
> Stephan
> 
> On Monday, December 22, 2014 7:38:26 AM UTC+1, Magnus Bäck wrote:
> 
> > On Tuesday, December 16, 2014 at 10:03 CET,  
> > stephanos [stephan...@gmail.com](mailto:stephan...@gmail.com) wrote:
> > 
> > > we are using Google App Engine to host our SaaS app. Google offers a  
> > > nice log browser but it is way too sloooow. So one of my colleagues  
> > > suggested we pipe our logs to logstash and make them accessible via  
> > > Kibana. So far so good, we managed to set everything up.  
> > > But when Kibana was shown to the other team members they weren't  
> > > really excited. It was much faster, yes. It allowed to make better  
> > > queries, yes. BUT it broke the pattern they knew from the Google App  
> > > Engine log browser:  
> > > /some-request  
> > > log message 1  
> > > log message 2  
> > > /another-request  
> > > log message 3  
> > > /yet-another-request  
> > > log message 4  
> > > While Kibana works like this:  
> > > log message 1 /some-request  
> > > log message 2 /some-request  
> > > log message 3 /another-request  
> > > log message 4 /yet-another-request  
> > > So basically App Engine groups log messages by request. To get my  
> > > team on board, can we make Kibana do the same?
> > 
> > Not out of the box, no. Kibana doesn't have any such contextual  
> > understanding of messages and currently can't be configured as  
> > such either.
> > 
> > --  
> > Magnus Bäck | Software Engineer, Development Tools  
> > [magnu...@sonymobile.com](mailto:magnu...@sonymobile.com) | Sony Mobile Communications

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0513eb37-5742-46c8-b7c6-fd56f609d0e4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0513eb37-5742-46c8-b7c6-fd56f609d0e4%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:42am UTC](https://discuss.elastic.co/t/kibana-group-by-request/21271/6 "2017-07-06T00:42:08Z")

</div>


