# Query into Logstash Monitoring Pipeline Data Array

**URL:** <https://discuss.elastic.co/t/query-into-logstash-monitoring-pipeline-data-array/171809>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [March 11, 2019, 4:39pm UTC](https://discuss.elastic.co/t/query-into-logstash-monitoring-pipeline-data-array/171809 "2019-03-11T16:39:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nielsoncr](https://avatars.discourse-cdn.com/v4/letter/n/c57346/32.png) [@nielsoncr](https://discuss.elastic.co/u/nielsoncr)\
**Post date:** [March 11, 2019, 4:39pm UTC](https://discuss.elastic.co/t/query-into-logstash-monitoring-pipeline-data-array/171809/1 "2019-03-11T16:39:53Z")

</div>

I would like to build an Alert (Watch) on monitoring data produced by Logstash. An abbreviated sample of the logstash\_stats data is below. I am interested in building a query that will return a result when logstash\_stats.pipeline[0].queue.events\_count is greater than X. So far I've been unable to write a query that will take the logstash\_stats.pipelines[0] syntax

```
  {
    "_index": ".monitoring-logstash-6-2019.03.11",
    "_type": "doc",
    "_id": "y9TJamkBWbgJUsLE8joK",
    "_score": 3.6381288,
    "_source": {
      "cluster_uuid": "Gmvza0htSEKw4GfM6sUKXQ",
      "timestamp": "2019-03-11T03:26:53.448Z",
      "interval_ms": 1000,
      "type": "logstash_stats",
      "source_node": {...}
      },
      "logstash_stats": {
        "timestamp": "2019-03-11T03:26:53.438Z",
        "pipelines": [
          {
            "ephemeral_id": "d80e58cb-e13f-4b1b-aa3c-e7f7821cd0e2",
            "queue": {
              "type": "persisted",
              "events_count": 60 ` **<-- I want to be able to query this for a number greater than X** `
            },
            "id": "main",
            "reloads": {
              "failures": 0,
              "successes": 0
            },
            "hash": "8870edd63dd058e41cf8bf803c2dbd1f615b1bad9400c57958de516f8ed2661c"
          }
        ],
        "queue": {
          "events_count": 60
        }
      }
    }
  }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2019, 4:39pm UTC](https://discuss.elastic.co/t/query-into-logstash-monitoring-pipeline-data-array/171809/2 "2019-04-08T16:39:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
