I am using Logstash 1.4.1, elasticsearch 1.1.1, kibana 3.1 for analyzing my
logs. I get the parsed fields (from log) in Kibana 3.
Now, I have often query on a particular field for many strings. Eg:
auth_message is a field and I may have to query for like 20 different
strings (all together or separately).
If together:
auth_message: "login failed" OR "user XYZ" OR "authentication failure" OR .........
So user cannot remember 20 strings for a field to be searched for. Is there
a way to store or present it to user to select the strings he wants to
search for.
I am using Logstash 1.4.1, elasticsearch 1.1.1, kibana 3.1 for analyzing
my logs. I get the parsed fields (from log) in Kibana 3.
Now, I have often query on a particular field for many strings. Eg:
auth_message is a field and I may have to query for like 20 different
strings (all together or separately).
If together:
auth_message: "login failed" OR "user XYZ" OR "authentication failure" OR .........
So user cannot remember 20 strings for a field to be searched for. Is
there a way to store or present it to user to select the strings he wants
to search for.
I am using Logstash 1.4.1, elasticsearch 1.1.1, kibana 3.1 for
analyzing my logs. I get the parsed fields (from log) in Kibana 3.
Now, I have often query on a particular field for many strings. Eg:
auth_message is a field and I may have to query for like 20 different
strings (all together or separately).
If together:
auth_message: "login failed" OR "user XYZ" OR "authentication failure" OR .........
So user cannot remember 20 strings for a field to be searched for. Is
there a way to store or present it to user to select the strings he wants
to search for.
Can this be done using ELK ?? Please help
--
You received this message because you are subscribed to the Google Groups
"elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an
email to elasticsearch+unsubscribe@googlegroups.com.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.