Percolator Question

Hi there,

We want to do more with the data we're indexing, so that we can do some
real-time anomaly detection. We've been looking at the percolator feature
as a simple starting point, but I just want to get an idea of if what I'm
asking is possible.

We want a stored query that will match when a document comes through, and
is e.g. "the 10th delete request performed by user Foo in the last two
days!". For documents like {user: "foo", action: "delete", object:

Can Percolator queries do that - look at more than just the document coming
through? Is there a good example or tutorial around that? Should we be
looking at something else for this kind of data analysis?


You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
To view this discussion on the web visit
For more options, visit