# Logstash Aggregation concepts

**URL:** <https://discuss.elastic.co/t/logstash-aggregation-concepts/81963>\
**Category:** Logstash\
**Created:** [April 11, 2017, 11:10am UTC](https://discuss.elastic.co/t/logstash-aggregation-concepts/81963 "2017-04-11T11:10:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jonesthomas](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Post date:** [April 11, 2017, 11:10am UTC](https://discuss.elastic.co/t/logstash-aggregation-concepts/81963/1 "2017-04-11T11:10:08Z")

</div>

hi,im learning little deep in logstash filter concept. i have a sample log message,i want to aggregate them,group the particular event,and want to custom label the field..  
This is my sample log message,Someone Guide me.

[{  
"logID": 1,  
"organizationID": 1,  
"userID": 1001,  
"appID": 123,  
"moduleID": 1,  
"screenID": 213,  
"timeStamp": "2017-03-15 10:06:26",  
"action": "Login",  
"purpose": "log",  
"role": "Doctor",  
"location": "Hospital",  
"ipaddress": "192.168.1.3",  
"networkType": "desktop",  
"method": "getAll",  
"category": "normal",  
"description": "successfully logged in"  
}, {  
"logID": 2,  
"organizationID": 1,  
"userID": 201,  
"appID": 201,  
"moduleID": 2,  
"screenID": 224,  
"timeStamp": "2017-03-15 10:36:06",  
"action": "Login",  
"purpose": "log",  
"role": "Nurse",  
"location": "Clinic",  
"ipaddress": "192.168.2.6",  
"networkType": "tablet",  
"method": "addVitals",  
"category": "minor error",  
"description": "error logged"  
}, {  
"logID": 3,  
"organizationID": 1,  
"userID": 1245,  
"appID": 654,  
"moduleID": 2,  
"screenID": 225,  
"timeStamp": "2017-03-15 10:46:26",  
"action": "Book\_apt",  
"purpose": "log",  
"role": "Patient",  
"location": "public",  
"ipaddress": "192.178.1.5",  
"networkType": "mobile",  
"method": "getByID",  
"category": "severe error",  
"description": "error logged"  
}, {  
"logID": 4,  
"organizationID": 1,  
"userID": 1001,  
"appID": 123,  
"moduleID": 1,  
"screenID": 213,  
"timeStamp": "2017-03-15 11:16:26",  
"action": "Logout",  
"purpose": "log",  
"role": "Doctor",  
"location": "Hospital",  
"ipaddress": "192.168.1.3",  
"networkType": "desktop",  
"method": "getAll",  
"category": "normal",  
"description": "successfully logged out"  
}, {  
"logID": 5,  
"organizationID": 1,  
"userID": 2365,  
"appID": 321,  
"moduleID": 3,  
"screenID": 654,  
"timeStamp": "2017-03-15 11:56:36",  
"action": "Find\_doctor",  
"purpose": "log",  
"role": "Patient",  
"location": "public",  
"ipaddress": "192.178.6.8",  
"networkType": "desktop",  
"method": "getByName",  
"category": "normal",  
"description": "Doctor found"  
}]

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [April 12, 2017, 1:09am UTC](https://discuss.elastic.co/t/logstash-aggregation-concepts/81963/2 "2017-04-12T01:09:50Z")

</div>

I would create the visualization in Kibana and then save it, then you can look at how they did it. Which would provide you a quick example of how they do it.  
To view just go to Kibana-\>settings-\>objects-\>visualizations and find the vis you saved

Each Aggregation works a little differently , and reading up on it would be a good start.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2017, 1:21am UTC](https://discuss.elastic.co/t/logstash-aggregation-concepts/81963/3 "2017-05-10T01:21:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
