# Return Logstash Failed User logons by day and return code

**URL:** <https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260>\
**Category:** Elasticsearch\
**Created:** [December 15, 2014, 4:30pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260 "2014-12-15T16:30:05Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rod\_Clayton](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Rod\_Clayton](https://discuss.elastic.co/u/Rod_Clayton)\
**Post date:** [December 15, 2014, 4:30pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/1 "2014-12-15T16:30:05Z")

</div>

I have loaded login data into Elasticsearch using Logstash.

I have fields: username retcd workstation.

I want to query and get a count of failed logon requests by username and  
workstation on a given day.

The indexes are named like logstash-2014.11.18.

What would a query for this look like on the day listed above?

Thanks,  
Rod

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Sachin\_Divekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sachin_divekar/32/1046_2.png) [@Sachin\_Divekar](https://discuss.elastic.co/u/Sachin_Divekar)\
**Post date:** [December 15, 2014, 6:03pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/2 "2014-12-15T18:03:01Z")

</div>

Hi,

Can you share some sample data and desired output?

Sachin Divekar

On Mon, Dec 15, 2014, 10:00 PM Rod Clayton [rod.clayton@gmail.com](mailto:rod.clayton@gmail.com) wrote:

> I have loaded login data into Elasticsearch using Logstash.
> 
> I have fields: username retcd workstation.
> 
> I want to query and get a count of failed logon requests by username and  
> workstation on a given day.
> 
> The indexes are named like logstash-2014.11.18.
> 
> What would a query for this look like on the day listed above?
> 
> Thanks,  
> Rod
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CA%2BA8H7n2dNMJjC\_1d7m%2B8vsA2rTNyewvGNkMiPZTHV\_4iCpHOA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CA%2BA8H7n2dNMJjC_1d7m%2B8vsA2rTNyewvGNkMiPZTHV_4iCpHOA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Rod\_Clayton](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Rod\_Clayton](https://discuss.elastic.co/u/Rod_Clayton)\
**Post date:** [December 15, 2014, 6:58pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/3 "2014-12-15T18:58:47Z")

</div>

Are would the logstash debug output be okay, or are you asking for  
something else?

Obviously I am new at this.

Thanks,  
Rod

On Monday, December 15, 2014 1:03:07 PM UTC-5, Sachin Divekar wrote:

> Hi,
> 
> Can you share some sample data and desired output?
> 
> Sachin Divekar
> 
> On Mon, Dec 15, 2014, 10:00 PM Rod Clayton \<[rod.c...@gmail.com](mailto:rod.c...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > I have loaded login data into Elasticsearch using Logstash.
> > 
> > I have fields: username retcd workstation.
> > 
> > I want to query and get a count of failed logon requests by username and  
> > workstation on a given day.
> > 
> > The indexes are named like logstash-2014.11.18.
> > 
> > What would a query for this look like on the day listed above?
> > 
> > Thanks,  
> > Rod
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/bc68c3ae-dba2-4bbb-a873-8ded53c49874%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/bc68c3ae-dba2-4bbb-a873-8ded53c49874%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Rod\_Clayton](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Rod\_Clayton](https://discuss.elastic.co/u/Rod_Clayton)\
**Post date:** [December 15, 2014, 8:08pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/4 "2014-12-15T20:08:41Z")

</div>

The logstash debug for the input logs look like:

{  
"message" =\>  
"37208057\tSecurity\tMicrosoft-Windows-Security-Auditing\tSUCCESS  
AUDIT\tserver.myorg.org\t11/18/2014 12:13:32 AM\t4776\tNone\t"The computer  
attempted to validate the credentials for an account. Authentication  
Package: MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0 Logon Account: joe Source  
Workstation: joescomputer Error Code: 0x0 "",  
"@version" =\> "1",  
"@timestamp" =\> "2014-11-18T05:13:32.000Z",  
"host" =\> "0:0:0:0:0:0:0:1:51947",  
"type" =\> "logons",  
"recno" =\> "37208057",  
"logtype" =\> "Security",  
"status" =\> "SUCCESS",  
"hostname" =\> "[server.myorg.org](http://server.myorg.org)",  
"eventCode" =\> "4776",  
"username" =\> "joe",  
"workstation" =\> "joescomputer",  
"retcd" =\> "0x0",  
"received\_at" =\> "2014-12-15 19:25:49 UTC",  
"received\_from" =\> "0:0:0:0:0:0:0:1:51947"  
}

I have obscured the host names and accounts, but the fields are the same.

I am hoping for output like:

username workstation name error code Count  
root maryscomputer 6a 100  
joe lab1 6a 5  
joe lab2 6a 2  
mary maryscomputer 6a 1

This assumes that the detail records were all dated the same day.  
I am expecting that this is going to come back in a JSON format that I will  
have to format to look like above.

Is this what you wanted?

On Monday, December 15, 2014 1:03:07 PM UTC-5, Sachin Divekar wrote:

> Hi,
> 
> Can you share some sample data and desired output?
> 
> Sachin Divekar
> 
> On Mon, Dec 15, 2014, 10:00 PM Rod Clayton \<[rod.c...@gmail.com](mailto:rod.c...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > I have loaded login data into Elasticsearch using Logstash.
> > 
> > I have fields: username retcd workstation.
> > 
> > I want to query and get a count of failed logon requests by username and  
> > workstation on a given day.
> > 
> > The indexes are named like logstash-2014.11.18.
> > 
> > What would a query for this look like on the day listed above?
> > 
> > Thanks,  
> > Rod
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Sachin\_Divekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sachin_divekar/32/1046_2.png) [@Sachin\_Divekar](https://discuss.elastic.co/u/Sachin_Divekar)\
**Post date:** [December 16, 2014, 3:12am UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/5 "2014-12-16T03:12:55Z")

</div>

Hi,

Share output of [http://localhost:9200/foo/\_search?pretty=true&q=\*:](http://localhost:9200/foo/_search?pretty=true&q=*:)\*  
substitute foo with name of your index.  
Use gist to share the output. I suggest, read  
[Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/help/)

Sachin Divekar

On Tue, Dec 16, 2014, 1:38 AM Rod Clayton [rod.clayton@gmail.com](mailto:rod.clayton@gmail.com) wrote:

> The logstash debug for the input logs look like:
> 
> {  
> "message" =\>  
> "37208057\tSecurity\tMicrosoft-Windows-Security-Auditing\tSUCCESS AUDIT  
> [tserver.myorg.org](http://tserver.myorg.org)\t11/18/2014 12:13:32 AM\t4776\tNone\t"The computer  
> attempted to validate the credentials for an account. Authentication  
> Package: MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0 Logon Account: joe Source  
> Workstation: joescomputer Error Code: 0x0 "",  
> "@version" =\> "1",  
> "@timestamp" =\> "2014-11-18T05:13:32.000Z",  
> "host" =\> "0:0:0:0:0:0:0:1:51947",  
> "type" =\> "logons",  
> "recno" =\> "37208057",  
> "logtype" =\> "Security",  
> "status" =\> "SUCCESS",  
> "hostname" =\> "[server.myorg.org](http://server.myorg.org)",  
> "eventCode" =\> "4776",  
> "username" =\> "joe",  
> "workstation" =\> "joescomputer",  
> "retcd" =\> "0x0",  
> "received\_at" =\> "2014-12-15 19:25:49 UTC",  
> "received\_from" =\> "0:0:0:0:0:0:0:1:51947"  
> }
> 
> I have obscured the host names and accounts, but the fields are the same.
> 
> I am hoping for output like:
> 
> username workstation name error code Count  
> root maryscomputer 6a 100  
> joe lab1 6a 5  
> joe lab2 6a 2  
> mary maryscomputer 6a 1
> 
> This assumes that the detail records were all dated the same day.  
> I am expecting that this is going to come back in a JSON format that I  
> will have to format to look like above.
> 
> Is this what you wanted?
> 
> On Monday, December 15, 2014 1:03:07 PM UTC-5, Sachin Divekar wrote:
> 
> > Hi,
> > 
> > Can you share some sample data and desired output?
> > 
> > Sachin Divekar
> > 
> > On Mon, Dec 15, 2014, 10:00 PM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com) wrote:
> 
> I have loaded login data into Elasticsearch using Logstash.
> 
> > > I have fields: username retcd workstation.
> > > 
> > > I want to query and get a count of failed logon requests by username and  
> > > workstation on a given day.
> > > 
> > > The indexes are named like logstash-2014.11.18.
> > > 
> > > What would a query for this look like on the day listed above?
> > > 
> > > Thanks,  
> > > Rod
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.
> > 
> > To unsubscribe from this group and stop receiving emails from it, send an
> > 
> > > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > 
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%  
> > > [40googlegroups.com](http://40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CA%2BA8H7%3DFpRs5gKJpAJ9BFGoGnH%2Bwzt89sF9u7PxU33Eivehdrg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CA%2BA8H7%3DFpRs5gKJpAJ9BFGoGnH%2Bwzt89sF9u7PxU33Eivehdrg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Rod\_Clayton](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Rod\_Clayton](https://discuss.elastic.co/u/Rod_Clayton)\
**Post date:** [December 16, 2014, 1:31pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/6 "2014-12-16T13:31:00Z")

</div>

Dear Sachin,

Here is the GIST with the output you requested:

ka3bhy [https://gist.github.com/ka3bhy](https://gist.github.com/ka3bhy) / _gist:082a5410d36264521ccb  
 [https://gist.github.com/ka3bhy/082a5410d36264521ccb](https://gist.github.com/ka3bhy/082a5410d36264521ccb)_

On Monday, December 15, 2014 10:13:02 PM UTC-5, Sachin Divekar wrote:

> Hi,
> 
> Share output of [http://localhost:9200/foo/\_search?pretty=true&q=\*:](http://localhost:9200/foo/_search?pretty=true&q=*:)\*  
> substitute foo with name of your index.  
> Use gist to share the output. I suggest, read  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/help/)
> 
> Sachin Divekar
> 
> On Tue, Dec 16, 2014, 1:38 AM Rod Clayton \<[rod.c...@gmail.com](mailto:rod.c...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > The logstash debug for the input logs look like:
> > 
> > {  
> > "message" =\>  
> > "37208057\tSecurity\tMicrosoft-Windows-Security-Auditing\tSUCCESS AUDIT  
> > [tserver.myorg.org](http://tserver.myorg.org)\t11/18/2014 12:13:32 AM\t4776\tNone\t"The computer  
> > attempted to validate the credentials for an account. Authentication  
> > Package: MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0 Logon Account: joe Source  
> > Workstation: joescomputer Error Code: 0x0 "",  
> > "@version" =\> "1",  
> > "@timestamp" =\> "2014-11-18T05:13:32.000Z",  
> > "host" =\> "0:0:0:0:0:0:0:1:51947",  
> > "type" =\> "logons",  
> > "recno" =\> "37208057",  
> > "logtype" =\> "Security",  
> > "status" =\> "SUCCESS",  
> > "hostname" =\> "[server.myorg.org](http://server.myorg.org)",  
> > "eventCode" =\> "4776",  
> > "username" =\> "joe",  
> > "workstation" =\> "joescomputer",  
> > "retcd" =\> "0x0",  
> > "received\_at" =\> "2014-12-15 19:25:49 UTC",  
> > "received\_from" =\> "0:0:0:0:0:0:0:1:51947"  
> > }
> > 
> > I have obscured the host names and accounts, but the fields are the same.
> > 
> > I am hoping for output like:
> > 
> > username workstation name error code Count  
> > root maryscomputer 6a 100  
> > joe lab1 6a 5  
> > joe lab2 6a 2  
> > mary maryscomputer 6a 1
> > 
> > This assumes that the detail records were all dated the same day.  
> > I am expecting that this is going to come back in a JSON format that I  
> > will have to format to look like above.
> > 
> > Is this what you wanted?
> > 
> > On Monday, December 15, 2014 1:03:07 PM UTC-5, Sachin Divekar wrote:
> > 
> > > Hi,
> > > 
> > > Can you share some sample data and desired output?
> > > 
> > > Sachin Divekar
> > > 
> > > On Mon, Dec 15, 2014, 10:00 PM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com) wrote:
> > 
> > I have loaded login data into Elasticsearch using Logstash.
> > 
> > > > I have fields: username retcd workstation.
> > > > 
> > > > I want to query and get a count of failed logon requests by username  
> > > > and workstation on a given day.
> > > > 
> > > > The indexes are named like logstash-2014.11.18.
> > > > 
> > > > What would a query for this look like on the day listed above?
> > > > 
> > > > Thanks,  
> > > > Rod
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google  
> > > > Groups "elasticsearch" group.
> > > 
> > > To unsubscribe from this group and stop receiving emails from it, send
> > > 
> > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > 
> > > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > > msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%  
> > > > [40googlegroups.com](http://40googlegroups.com)  
> > > > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > .  
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google Groups  
> > > "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send an  
> > > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > > To view this discussion on the web visit  
> > > [https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Sachin\_Divekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sachin_divekar/32/1046_2.png) [@Sachin\_Divekar](https://discuss.elastic.co/u/Sachin_Divekar)\
**Post date:** [December 16, 2014, 2:31pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/7 "2014-12-16T14:31:37Z")

</div>

Hi Rod,

Try following URL

[http://localhost:9200/\_search?q=status:](http://localhost:9200/_search?q=status:) FAILURE&pretty

In output you will find something like following

* * *

"hits": {  
"total": 7,  
"max\_score": 1,  
"hits": [

* * *

So in "hits" block value of "total" field is your count of failed logon  
requests.

For understanding search API and output of search query refer

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Regards  
Sachin Divekar

On Tue Dec 16 2014 at 7:01:02 PM Rod Clayton [rod.clayton@gmail.com](mailto:rod.clayton@gmail.com) wrote:

> Dear Sachin,
> 
> Here is the GIST with the output you requested:
> 
> ka3bhy [https://gist.github.com/ka3bhy](https://gist.github.com/ka3bhy) / _gist:082a5410d36264521ccb  
> [https://gist.github.com/ka3bhy/082a5410d36264521ccb](https://gist.github.com/ka3bhy/082a5410d36264521ccb)_
> 
> On Monday, December 15, 2014 10:13:02 PM UTC-5, Sachin Divekar wrote:
> 
> > Hi,
> > 
> > Share output of [http://localhost:9200/foo/\_search?pretty=true&q=\*:](http://localhost:9200/foo/_search?pretty=true&q=*:)\*  
> > substitute foo with name of your index.  
> > Use gist to share the output. I suggest, read  
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/help/)
> > 
> > Sachin Divekar
> > 
> > On Tue, Dec 16, 2014, 1:38 AM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com) wrote:
> 
> The logstash debug for the input logs look like:
> 
> > > {  
> > > "message" =\> "37208057\tSecurity\tMicrosoft-Windows-Security-Auditing\tSUCCESS  
> > > AUDIT\tserver.myorg.org\t11/18/2014 12:13:32 AM\t4776\tNone\t"The  
> > > computer attempted to validate the credentials for an account.  
> > > Authentication Package: MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0 Logon  
> > > Account: joe Source Workstation: joescomputer Error Code: 0x0 "",  
> > > "@version" =\> "1",  
> > > "@timestamp" =\> "2014-11-18T05:13:32.000Z",  
> > > "host" =\> "0:0:0:0:0:0:0:1:51947",  
> > > "type" =\> "logons",  
> > > "recno" =\> "37208057",  
> > > "logtype" =\> "Security",  
> > > "status" =\> "SUCCESS",  
> > > "hostname" =\> "[server.myorg.org](http://server.myorg.org)",  
> > > "eventCode" =\> "4776",  
> > > "username" =\> "joe",  
> > > "workstation" =\> "joescomputer",  
> > > "retcd" =\> "0x0",  
> > > "received\_at" =\> "2014-12-15 19:25:49 UTC",  
> > > "received\_from" =\> "0:0:0:0:0:0:0:1:51947"  
> > > }
> > > 
> > > I have obscured the host names and accounts, but the fields are the same.
> > > 
> > > I am hoping for output like:
> > > 
> > > username workstation name error code Count  
> > > root maryscomputer 6a 100  
> > > joe lab1 6a 5  
> > > joe lab2 6a 2  
> > > mary maryscomputer 6a 1
> > > 
> > > This assumes that the detail records were all dated the same day.  
> > > I am expecting that this is going to come back in a JSON format that I  
> > > will have to format to look like above.
> > > 
> > > Is this what you wanted?
> > > 
> > > On Monday, December 15, 2014 1:03:07 PM UTC-5, Sachin Divekar wrote:
> > > 
> > > > Hi,
> > > > 
> > > > Can you share some sample data and desired output?
> > > > 
> > > > Sachin Divekar
> > > > 
> > > > On Mon, Dec 15, 2014, 10:00 PM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com) wrote:
> > > 
> > > I have loaded login data into Elasticsearch using Logstash.
> > > 
> > > > > I have fields: username retcd workstation.
> > > > > 
> > > > > I want to query and get a count of failed logon requests by username  
> > > > > and workstation on a given day.
> > > > > 
> > > > > The indexes are named like logstash-2014.11.18.
> > > > > 
> > > > > What would a query for this look like on the day listed above?
> > > > > 
> > > > > Thanks,  
> > > > > Rod
> > > > > 
> > > > > --  
> > > > > You received this message because you are subscribed to the Google  
> > > > > Groups "elasticsearch" group.
> > > > 
> > > > To unsubscribe from this group and stop receiving emails from it, send
> > > > 
> > > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > > 
> > > > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > > > msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40goo  
> > > > > [glegroups.com](http://glegroups.com)  
> > > > > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > > .  
> > > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google  
> > > > Groups "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > 
> > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)
> > 
> > > msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%  
> > > [40googlegroups.com](http://40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CA%2BA8H7nK5%3DpwTbkcH5ND8-30YxXis57uuDuHdKDwogGzmrDUhQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CA%2BA8H7nK5%3DpwTbkcH5ND8-30YxXis57uuDuHdKDwogGzmrDUhQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Sachin\_Divekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sachin_divekar/32/1046_2.png) [@Sachin\_Divekar](https://discuss.elastic.co/u/Sachin_Divekar)\
**Post date:** [December 16, 2014, 2:38pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/8 "2014-12-16T14:38:05Z")

</div>

I had mistakenly put extra space in the URL. Corrected URL is  
[http://localhost:9200/\_search?q=status:FAILURE&pretty](http://localhost:9200/_search?q=status:FAILURE&pretty)

Regards  
Sachin Divekar

On Tue Dec 16 2014 at 8:01:37 PM Sachin Divekar [ssd532@gmail.com](mailto:ssd532@gmail.com) wrote:

> Hi Rod,
> 
> Try following URL
> 
> [http://localhost:9200/\_search?q=status:](http://localhost:9200/_search?q=status:) FAILURE&pretty
> 
> In output you will find something like following
> 
> * * *
> 
> "hits": {  
> "total": 7,  
> "max\_score": 1,  
> "hits": [
> 
> * * *
> 
> So in "hits" block value of "total" field is your count of failed logon  
> requests.
> 
> For understanding search API and output of search query refer  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/_the_search_api.html)
> 
> Regards  
> Sachin Divekar
> 
> On Tue Dec 16 2014 at 7:01:02 PM Rod Clayton [rod.clayton@gmail.com](mailto:rod.clayton@gmail.com)  
> wrote:
> 
> > Dear Sachin,
> > 
> > Here is the GIST with the output you requested:
> > 
> > ka3bhy [https://gist.github.com/ka3bhy](https://gist.github.com/ka3bhy) / _gist:082a5410d36264521ccb  
> > [https://gist.github.com/ka3bhy/082a5410d36264521ccb](https://gist.github.com/ka3bhy/082a5410d36264521ccb)_
> > 
> > On Monday, December 15, 2014 10:13:02 PM UTC-5, Sachin Divekar wrote:
> > 
> > > Hi,
> > > 
> > > Share output of [http://localhost:9200/foo/\_search?pretty=true&q=\*:](http://localhost:9200/foo/_search?pretty=true&q=*:)\*  
> > > substitute foo with name of your index.  
> > > Use gist to share the output. I suggest, read  
> > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/help/)
> > > 
> > > Sachin Divekar
> > > 
> > > On Tue, Dec 16, 2014, 1:38 AM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com) wrote:
> > 
> > The logstash debug for the input logs look like:
> > 
> > > > {  
> > > > "message" =\> "37208057\tSecurity\tMicrosoft-Windows-Security-  
> > > > Auditing\tSUCCESS AUDIT\tserver.myorg.org\t11/18/2014 12:13:32  
> > > > AM\t4776\tNone\t"The computer attempted to validate the credentials for an  
> > > > account. Authentication Package: MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0  
> > > > Logon Account: joe Source Workstation: joescomputer Error Code: 0x0 "",  
> > > > "@version" =\> "1",  
> > > > "@timestamp" =\> "2014-11-18T05:13:32.000Z",  
> > > > "host" =\> "0:0:0:0:0:0:0:1:51947",  
> > > > "type" =\> "logons",  
> > > > "recno" =\> "37208057",  
> > > > "logtype" =\> "Security",  
> > > > "status" =\> "SUCCESS",  
> > > > "hostname" =\> "[server.myorg.org](http://server.myorg.org)",  
> > > > "eventCode" =\> "4776",  
> > > > "username" =\> "joe",  
> > > > "workstation" =\> "joescomputer",  
> > > > "retcd" =\> "0x0",  
> > > > "received\_at" =\> "2014-12-15 19:25:49 UTC",  
> > > > "received\_from" =\> "0:0:0:0:0:0:0:1:51947"  
> > > > }
> > > > 
> > > > I have obscured the host names and accounts, but the fields are the  
> > > > same.
> > > > 
> > > > I am hoping for output like:
> > > > 
> > > > username workstation name error code Count  
> > > > root maryscomputer 6a 100  
> > > > joe lab1 6a 5  
> > > > joe lab2 6a 2  
> > > > mary maryscomputer 6a 1
> > > > 
> > > > This assumes that the detail records were all dated the same day.  
> > > > I am expecting that this is going to come back in a JSON format that I  
> > > > will have to format to look like above.
> > > > 
> > > > Is this what you wanted?
> > > > 
> > > > On Monday, December 15, 2014 1:03:07 PM UTC-5, Sachin Divekar wrote:
> > > > 
> > > > > Hi,
> > > > > 
> > > > > Can you share some sample data and desired output?
> > > > > 
> > > > > Sachin Divekar
> > > > > 
> > > > > On Mon, Dec 15, 2014, 10:00 PM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com) wrote:
> > > > 
> > > > I have loaded login data into Elasticsearch using Logstash.
> > > > 
> > > > > > I have fields: username retcd workstation.
> > > > > > 
> > > > > > I want to query and get a count of failed logon requests by username  
> > > > > > and workstation on a given day.
> > > > > > 
> > > > > > The indexes are named like logstash-2014.11.18.
> > > > > > 
> > > > > > What would a query for this look like on the day listed above?
> > > > > > 
> > > > > > Thanks,  
> > > > > > Rod
> > > > > > 
> > > > > > --  
> > > > > > You received this message because you are subscribed to the Google  
> > > > > > Groups "elasticsearch" group.
> > > > > 
> > > > > To unsubscribe from this group and stop receiving emails from it, send
> > > > > 
> > > > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > > > 
> > > > > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > > > > msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40goo  
> > > > > > [glegroups.com](http://glegroups.com)  
> > > > > > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > > > .  
> > > > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > > > 
> > > > > --  
> > > > > You received this message because you are subscribed to the Google  
> > > > > Groups "elasticsearch" group.  
> > > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > 
> > > To view this discussion on the web visit [https://groups.google.com/d/ms](https://groups.google.com/d/ms)
> > > 
> > > > gid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40goo  
> > > > [glegroups.com](http://glegroups.com)  
> > > > [https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > .  
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google Groups  
> > > "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send an  
> > > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%  
> > > [40googlegroups.com](http://40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CA%2BA8H7kDZ5zX4m4%3D%2BwKGFaKkkG9tAhKBDBgcqwYm8%2B%2Bmx-k7Mw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CA%2BA8H7kDZ5zX4m4%3D%2BwKGFaKkkG9tAhKBDBgcqwYm8%2B%2Bmx-k7Mw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Rod\_Clayton](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Rod\_Clayton](https://discuss.elastic.co/u/Rod_Clayton)\
**Post date:** [December 16, 2014, 3:44pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/9 "2014-12-16T15:44:03Z")

</div>

Dear Sachin,

I want to aggregate them by username and workstation and get a count. I  
need to produce a report if there are too many failures for an account.

I figured out how to limit the search to a particular day by saying  
[http://http](http://http)://localhost:9200/logstash-2014.11.19/\_search?q=status:%20FAILURE&pretty

I am looking for an example to aggregate on a couple of fields and get a  
count by value.

Is that possible?

Thanks,  
Rod

On Tuesday, December 16, 2014 9:38:12 AM UTC-5, Sachin Divekar wrote:

> I had mistakenly put extra space in the URL. Corrected URL is  
> [http://localhost:9200/\_search?q=status:FAILURE&pretty](http://localhost:9200/_search?q=status:FAILURE&pretty)
> 
> Regards  
> Sachin Divekar
> 
> On Tue Dec 16 2014 at 8:01:37 PM Sachin Divekar \<[ssd...@gmail.com](mailto:ssd...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > Hi Rod,
> > 
> > Try following URL
> > 
> > [http://localhost:9200/\_search?q=status:](http://localhost:9200/_search?q=status:) FAILURE&pretty
> > 
> > In output you will find something like following
> > 
> > * * *
> > 
> > "hits": {  
> > "total": 7,  
> > "max\_score": 1,  
> > "hits": [
> > 
> > * * *
> > 
> > So in "hits" block value of "total" field is your count of failed logon  
> > requests.
> > 
> > For understanding search API and output of search query refer  
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/_the_search_api.html)
> > 
> > Regards  
> > Sachin Divekar
> > 
> > On Tue Dec 16 2014 at 7:01:02 PM Rod Clayton \<[rod.c...@gmail.com](mailto:rod.c...@gmail.com)  
> > \<javascript:\>\> wrote:
> > 
> > > Dear Sachin,
> > > 
> > > Here is the GIST with the output you requested:
> > > 
> > > ka3bhy [https://gist.github.com/ka3bhy](https://gist.github.com/ka3bhy) / _gist:082a5410d36264521ccb  
> > > [https://gist.github.com/ka3bhy/082a5410d36264521ccb](https://gist.github.com/ka3bhy/082a5410d36264521ccb)_
> > > 
> > > On Monday, December 15, 2014 10:13:02 PM UTC-5, Sachin Divekar wrote:
> > > 
> > > > Hi,
> > > > 
> > > > Share output of [http://localhost:9200/foo/\_search?pretty=true&q=\*:](http://localhost:9200/foo/_search?pretty=true&q=*:)\*  
> > > > substitute foo with name of your index.  
> > > > Use gist to share the output. I suggest, read  
> > > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/help/)
> > > > 
> > > > Sachin Divekar
> > > > 
> > > > On Tue, Dec 16, 2014, 1:38 AM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com) wrote:
> > > 
> > > The logstash debug for the input logs look like:
> > > 
> > > > > {  
> > > > > "message" =\> "37208057\tSecurity\tMicrosoft  
> > > > > -Windows-Security-Auditing\tSUCCESS AUDIT\tserver.myorg.org\t11/18/2014  
> > > > > 12:13:32 AM\t4776\tNone\t"The computer attempted to validate the  
> > > > > credentials for an account. Authentication Package:  
> > > > > MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0 Logon Account: joe Source  
> > > > > Workstation: joescomputer Error Code: 0x0 "",  
> > > > > "@version" =\> "1",  
> > > > > "@timestamp" =\> "2014-11-18T05:13:32.000Z",  
> > > > > "host" =\> "0:0:0:0:0:0:0:1:51947",  
> > > > > "type" =\> "logons",  
> > > > > "recno" =\> "37208057",  
> > > > > "logtype" =\> "Security",  
> > > > > "status" =\> "SUCCESS",  
> > > > > "hostname" =\> "[server.myorg.org](http://server.myorg.org)",  
> > > > > "eventCode" =\> "4776",  
> > > > > "username" =\> "joe",  
> > > > > "workstation" =\> "joescomputer",  
> > > > > "retcd" =\> "0x0",  
> > > > > "received\_at" =\> "2014-12-15 19:25:49 UTC",  
> > > > > "received\_from" =\> "0:0:0:0:0:0:0:1:51947"  
> > > > > }
> > > > > 
> > > > > I have obscured the host names and accounts, but the fields are the  
> > > > > same.
> > > > > 
> > > > > I am hoping for output like:
> > > > > 
> > > > > username workstation name error code Count  
> > > > > root maryscomputer 6a 100  
> > > > > joe lab1 6a 5  
> > > > > joe lab2 6a 2  
> > > > > mary maryscomputer 6a 1
> > > > > 
> > > > > This assumes that the detail records were all dated the same day.  
> > > > > I am expecting that this is going to come back in a JSON format that I  
> > > > > will have to format to look like above.
> > > > > 
> > > > > Is this what you wanted?
> > > > > 
> > > > > On Monday, December 15, 2014 1:03:07 PM UTC-5, Sachin Divekar wrote:
> > > > > 
> > > > > > Hi,
> > > > > > 
> > > > > > Can you share some sample data and desired output?
> > > > > > 
> > > > > > Sachin Divekar
> > > > > > 
> > > > > > On Mon, Dec 15, 2014, 10:00 PM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com)  
> > > > > > wrote:
> > > > > 
> > > > > I have loaded login data into Elasticsearch using Logstash.
> > > > > 
> > > > > > > I have fields: username retcd workstation.
> > > > > > > 
> > > > > > > I want to query and get a count of failed logon requests by username  
> > > > > > > and workstation on a given day.
> > > > > > > 
> > > > > > > The indexes are named like logstash-2014.11.18.
> > > > > > > 
> > > > > > > What would a query for this look like on the day listed above?
> > > > > > > 
> > > > > > > Thanks,  
> > > > > > > Rod
> > > > > > > 
> > > > > > > --  
> > > > > > > You received this message because you are subscribed to the Google  
> > > > > > > Groups "elasticsearch" group.
> > > > > > 
> > > > > > To unsubscribe from this group and stop receiving emails from it,
> > > > > > 
> > > > > > > send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > > > > 
> > > > > > > To view this discussion on the web visit  
> > > > > > > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e)  
> > > > > > > 6-478a-ad77-9418e5822296%[40googlegroups.com](http://40googlegroups.com)  
> > > > > > > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > > > > .  
> > > > > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > > > > 
> > > > > > --  
> > > > > > You received this message because you are subscribed to the Google  
> > > > > > Groups "elasticsearch" group.  
> > > > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > > 
> > > > To view this discussion on the web visit [https://groups.google.com/d/ms](https://groups.google.com/d/ms)
> > > > 
> > > > > gid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40goo  
> > > > > [glegroups.com](http://glegroups.com)  
> > > > > [https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > > .  
> > > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google  
> > > > Groups "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > > msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%  
> > > > [40googlegroups.com](http://40googlegroups.com)  
> > > > [https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > .  
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/21cb8c2a-d9bc-497c-a217-bea52dcc2632%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/21cb8c2a-d9bc-497c-a217-bea52dcc2632%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Sachin\_Divekar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sachin_divekar/32/1046_2.png) [@Sachin\_Divekar](https://discuss.elastic.co/u/Sachin_Divekar)\
**Post date:** [December 16, 2014, 6:17pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/10 "2014-12-16T18:17:44Z")

</div>

Hi Rod,

What you need to use is multi level terms aggregation. General format of  
such query is as following.

{  
"aggs": { "agg1": { "terms": { "field": "field1" }, "aggs": { "agg2": {  
"terms": { "field": "field2" }, "aggs": { "agg3": { "terms": { "field":  
"field3" }  
} } } } } }  
}

In your case you can use fleeing query

{ "aggs": { "users": { "terms": { "field": "username" }, "aggs": {  
"workstations": { "terms": { "field": "workstation" } } } } } }

Just to understand how it works you can play with sequence of aggs, users  
and workstations and see how the output changes.

Regards  
Sachin Divekar

--  
Sent from phone

On Tue, Dec 16, 2014, 9:14 PM Rod Clayton [rod.clayton@gmail.com](mailto:rod.clayton@gmail.com) wrote:

> Dear Sachin,
> 
> I want to aggregate them by username and workstation and get a count. I  
> need to produce a report if there are too many failures for an account.
> 
> I figured out how to limit the search to a particular day by saying http://  
> [http://localhost:9200/logstash-2014.11.19/\_search?q=status:%20FAILURE&pretty](http://localhost:9200/logstash-2014.11.19/_search?q=status:%20FAILURE&pretty)
> 
> I am looking for an example to aggregate on a couple of fields and get a  
> count by value.
> 
> Is that possible?
> 
> Thanks,  
> Rod
> 
> On Tuesday, December 16, 2014 9:38:12 AM UTC-5, Sachin Divekar wrote:
> 
> > I had mistakenly put extra space in the URL. Corrected URL is  
> > [http://localhost:9200/\_search?q=status:FAILURE&pretty](http://localhost:9200/_search?q=status:FAILURE&pretty)
> > 
> > Regards  
> > Sachin Divekar
> > 
> > On Tue Dec 16 2014 at 8:01:37 PM Sachin Divekar [ssd...@gmail.com](mailto:ssd...@gmail.com) wrote:
> 
> Hi Rod,
> 
> > > Try following URL
> > > 
> > > [http://localhost:9200/\_search?q=status:](http://localhost:9200/_search?q=status:) FAILURE&pretty
> > > 
> > > In output you will find something like following
> > > 
> > > * * *
> > > 
> > > "hits": {  
> > > "total": 7,  
> > > "max\_score": 1,  
> > > "hits": [
> > > 
> > > * * *
> > > 
> > > So in "hits" block value of "total" field is your count of failed logon  
> > > requests.
> > > 
> > > For understanding search API and output of search query refer  
> > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/)  
> > > current/\_the\_search\_api.html
> > > 
> > > Regards  
> > > Sachin Divekar
> > > 
> > > On Tue Dec 16 2014 at 7:01:02 PM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com) wrote:
> > 
> > Dear Sachin,
> > 
> > > > Here is the GIST with the output you requested:
> > > > 
> > > > ka3bhy [https://gist.github.com/ka3bhy](https://gist.github.com/ka3bhy) / _gist:082a5410d36264521ccb  
> > > > [https://gist.github.com/ka3bhy/082a5410d36264521ccb](https://gist.github.com/ka3bhy/082a5410d36264521ccb)_
> > > > 
> > > > On Monday, December 15, 2014 10:13:02 PM UTC-5, Sachin Divekar wrote:
> > > > 
> > > > > Hi,
> > > > > 
> > > > > Share output of [http://localhost:9200/foo/\_search?pretty=true&q=\*:](http://localhost:9200/foo/_search?pretty=true&q=*:)\*  
> > > > > substitute foo with name of your index.  
> > > > > Use gist to share the output. I suggest, read  
> > > > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/help/)
> > > > > 
> > > > > Sachin Divekar
> > > > > 
> > > > > On Tue, Dec 16, 2014, 1:38 AM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com) wrote:
> > > > 
> > > > The logstash debug for the input logs look like:
> > > > 
> > > > > > {  
> > > > > > "message" =\> "37208057\tSecurity\tMicrosoft  
> > > > > > -Windows-Security-Auditing\tSUCCESS AUDIT\tserver.myorg.org\t11/18/2014  
> > > > > > 12:13:32 AM\t4776\tNone\t"The computer attempted to validate the  
> > > > > > credentials for an account. Authentication Package:  
> > > > > > MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0 Logon Account: joe Source  
> > > > > > Workstation: joescomputer Error Code: 0x0 "",  
> > > > > > "@version" =\> "1",  
> > > > > > "@timestamp" =\> "2014-11-18T05:13:32.000Z",  
> > > > > > "host" =\> "0:0:0:0:0:0:0:1:51947",  
> > > > > > "type" =\> "logons",  
> > > > > > "recno" =\> "37208057",  
> > > > > > "logtype" =\> "Security",  
> > > > > > "status" =\> "SUCCESS",  
> > > > > > "hostname" =\> "[server.myorg.org](http://server.myorg.org)",  
> > > > > > "eventCode" =\> "4776",  
> > > > > > "username" =\> "joe",  
> > > > > > "workstation" =\> "joescomputer",  
> > > > > > "retcd" =\> "0x0",  
> > > > > > "received\_at" =\> "2014-12-15 19:25:49 UTC",  
> > > > > > "received\_from" =\> "0:0:0:0:0:0:0:1:51947"  
> > > > > > }
> > > > > > 
> > > > > > I have obscured the host names and accounts, but the fields are the  
> > > > > > same.
> > > > > > 
> > > > > > I am hoping for output like:
> > > > > > 
> > > > > > username workstation name error code Count  
> > > > > > root maryscomputer 6a 100  
> > > > > > joe lab1 6a 5  
> > > > > > joe lab2 6a 2  
> > > > > > mary maryscomputer 6a 1
> > > > > > 
> > > > > > This assumes that the detail records were all dated the same day.  
> > > > > > I am expecting that this is going to come back in a JSON format that  
> > > > > > I will have to format to look like above.
> > > > > > 
> > > > > > Is this what you wanted?
> > > > > > 
> > > > > > On Monday, December 15, 2014 1:03:07 PM UTC-5, Sachin Divekar wrote:
> > > > > > 
> > > > > > > Hi,
> > > > > > > 
> > > > > > > Can you share some sample data and desired output?
> > > > > > > 
> > > > > > > Sachin Divekar
> > > > > > > 
> > > > > > > On Mon, Dec 15, 2014, 10:00 PM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com)  
> > > > > > > wrote:
> > > > > > 
> > > > > > I have loaded login data into Elasticsearch using Logstash.
> > > > > > 
> > > > > > > > I have fields: username retcd workstation.
> > > > > > > > 
> > > > > > > > I want to query and get a count of failed logon requests by  
> > > > > > > > username and workstation on a given day.
> > > > > > > > 
> > > > > > > > The indexes are named like logstash-2014.11.18.
> > > > > > > > 
> > > > > > > > What would a query for this look like on the day listed above?
> > > > > > > > 
> > > > > > > > Thanks,  
> > > > > > > > Rod
> > > > > > > > 
> > > > > > > > --  
> > > > > > > > You received this message because you are subscribed to the Google  
> > > > > > > > Groups "elasticsearch" group.
> > > > > > > 
> > > > > > > To unsubscribe from this group and stop receiving emails from it,
> > > > > > > 
> > > > > > > > send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > > > > > 
> > > > > > > > To view this discussion on the web visit  
> > > > > > > > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e)  
> > > > > > > > 6-478a-ad77-9418e5822296%[40googlegroups.com](http://40googlegroups.com)  
> > > > > > > > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > > > > > .  
> > > > > > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > > > > > 
> > > > > > > --  
> > > > > > > You received this message because you are subscribed to the Google  
> > > > > > > Groups "elasticsearch" group.  
> > > > > > > To unsubscribe from this group and stop receiving emails from it,  
> > > > > > > send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > > > 
> > > > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)
> > > > > 
> > > > > > msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40goo  
> > > > > > [glegroups.com](http://glegroups.com)  
> > > > > > [https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > > > .  
> > > > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > > > 
> > > > > --  
> > > > > You received this message because you are subscribed to the Google  
> > > > > Groups "elasticsearch" group.  
> > > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > 
> > > To view this discussion on the web visit [https://groups.google.com/d/ms](https://groups.google.com/d/ms)
> > > 
> > > > gid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40goo  
> > > > [glegroups.com](http://glegroups.com)  
> > > > [https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > .  
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google Groups  
> > > "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send an  
> > > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > To view this discussion on the web visit  
> > > [https://groups.google.com/d/msgid/elasticsearch/21cb8c2a-d9bc-497c-a217-bea52dcc2632%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/21cb8c2a-d9bc-497c-a217-bea52dcc2632%40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/21cb8c2a-d9bc-497c-a217-bea52dcc2632%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/21cb8c2a-d9bc-497c-a217-bea52dcc2632%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CA%2BA8H7mshmZQ\_QQBTrpxigc3atYUJb3E0CeBCL4VcWbyQ%2BztrQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CA%2BA8H7mshmZQ_QQBTrpxigc3atYUJb3E0CeBCL4VcWbyQ%2BztrQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Rod\_Clayton](https://avatars.discourse-cdn.com/v4/letter/r/87869e/32.png) [@Rod\_Clayton](https://discuss.elastic.co/u/Rod_Clayton)\
**Post date:** [December 17, 2014, 8:19pm UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/11 "2014-12-17T20:19:51Z")

</div>

Dear Sachin,

I got your query working with curl.

Thanks for your help!!!

Rod

On Tuesday, December 16, 2014 1:17:56 PM UTC-5, Sachin Divekar wrote:

> Hi Rod,
> 
> What you need to use is multi level terms aggregation. General format of  
> such query is as following.
> 
> {  
> "aggs": { "agg1": { "terms": { "field": "field1" }, "aggs": { "agg2": {  
> "terms": { "field": "field2" }, "aggs": { "agg3": { "terms": { "field":  
> "field3" }  
> } } } } } }  
> }
> 
> In your case you can use fleeing query
> 
> { "aggs": { "users": { "terms": { "field": "username" }, "aggs": {  
> "workstations": { "terms": { "field": "workstation" } } } } } }
> 
> Just to understand how it works you can play with sequence of aggs, users  
> and workstations and see how the output changes.
> 
> Regards  
> Sachin Divekar
> 
> --  
> Sent from phone
> 
> On Tue, Dec 16, 2014, 9:14 PM Rod Clayton \<[rod.c...@gmail.com](mailto:rod.c...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > Dear Sachin,
> > 
> > I want to aggregate them by username and workstation and get a count. I  
> > need to produce a report if there are too many failures for an account.
> > 
> > I figured out how to limit the search to a particular day by saying  
> > http://  
> > [http://localhost:9200/logstash-2014.11.19/\_search?q=status:%20FAILURE&pretty](http://localhost:9200/logstash-2014.11.19/_search?q=status:%20FAILURE&pretty)
> > 
> > I am looking for an example to aggregate on a couple of fields and get a  
> > count by value.
> > 
> > Is that possible?
> > 
> > Thanks,  
> > Rod
> > 
> > On Tuesday, December 16, 2014 9:38:12 AM UTC-5, Sachin Divekar wrote:
> > 
> > > I had mistakenly put extra space in the URL. Corrected URL is  
> > > [http://localhost:9200/\_search?q=status:FAILURE&pretty](http://localhost:9200/_search?q=status:FAILURE&pretty)
> > > 
> > > Regards  
> > > Sachin Divekar
> > > 
> > > On Tue Dec 16 2014 at 8:01:37 PM Sachin Divekar [ssd...@gmail.com](mailto:ssd...@gmail.com)  
> > > wrote:
> > 
> > Hi Rod,
> > 
> > > > Try following URL
> > > > 
> > > > [http://localhost:9200/\_search?q=status:](http://localhost:9200/_search?q=status:) FAILURE&pretty
> > > > 
> > > > In output you will find something like following
> > > > 
> > > > * * *
> > > > 
> > > > "hits": {  
> > > > "total": 7,  
> > > > "max\_score": 1,  
> > > > "hits": [
> > > > 
> > > > * * *
> > > > 
> > > > So in "hits" block value of "total" field is your count of failed logon  
> > > > requests.
> > > > 
> > > > For understanding search API and output of search query refer  
> > > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/)  
> > > > current/\_the\_search\_api.html
> > > > 
> > > > Regards  
> > > > Sachin Divekar
> > > > 
> > > > On Tue Dec 16 2014 at 7:01:02 PM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com)  
> > > > wrote:
> > > 
> > > Dear Sachin,
> > > 
> > > > > Here is the GIST with the output you requested:
> > > > > 
> > > > > ka3bhy [https://gist.github.com/ka3bhy](https://gist.github.com/ka3bhy) / _gist:082a5410d36264521ccb  
> > > > > [https://gist.github.com/ka3bhy/082a5410d36264521ccb](https://gist.github.com/ka3bhy/082a5410d36264521ccb)_
> > > > > 
> > > > > On Monday, December 15, 2014 10:13:02 PM UTC-5, Sachin Divekar wrote:
> > > > > 
> > > > > > Hi,
> > > > > > 
> > > > > > Share output of [http://localhost:9200/foo/\_search?pretty=true&q=\*:](http://localhost:9200/foo/_search?pretty=true&q=*:)\*  
> > > > > > substitute foo with name of your index.  
> > > > > > Use gist to share the output. I suggest, read  
> > > > > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/help/)
> > > > > > 
> > > > > > Sachin Divekar
> > > > > > 
> > > > > > On Tue, Dec 16, 2014, 1:38 AM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com) wrote:
> > > > > 
> > > > > The logstash debug for the input logs look like:
> > > > > 
> > > > > > > {  
> > > > > > > "message" =\> "37208057\tSecurity\tMicrosoft  
> > > > > > > -Windows-Security-Auditing\tSUCCESS AUDIT\tserver.myorg.org\t11/18/2014  
> > > > > > > 12:13:32 AM\t4776\tNone\t"The computer attempted to validate the  
> > > > > > > credentials for an account. Authentication Package:  
> > > > > > > MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0 Logon Account: joe Source  
> > > > > > > Workstation: joescomputer Error Code: 0x0 "",  
> > > > > > > "@version" =\> "1",  
> > > > > > > "@timestamp" =\> "2014-11-18T05:13:32.000Z",  
> > > > > > > "host" =\> "0:0:0:0:0:0:0:1:51947",  
> > > > > > > "type" =\> "logons",  
> > > > > > > "recno" =\> "37208057",  
> > > > > > > "logtype" =\> "Security",  
> > > > > > > "status" =\> "SUCCESS",  
> > > > > > > "hostname" =\> "[server.myorg.org](http://server.myorg.org)",  
> > > > > > > "eventCode" =\> "4776",  
> > > > > > > "username" =\> "joe",  
> > > > > > > "workstation" =\> "joescomputer",  
> > > > > > > "retcd" =\> "0x0",  
> > > > > > > "received\_at" =\> "2014-12-15 19:25:49 UTC",  
> > > > > > > "received\_from" =\> "0:0:0:0:0:0:0:1:51947"  
> > > > > > > }
> > > > > > > 
> > > > > > > I have obscured the host names and accounts, but the fields are the  
> > > > > > > same.
> > > > > > > 
> > > > > > > I am hoping for output like:
> > > > > > > 
> > > > > > > username workstation name error code Count  
> > > > > > > root maryscomputer 6a 100  
> > > > > > > joe lab1 6a 5  
> > > > > > > joe lab2 6a 2  
> > > > > > > mary maryscomputer 6a 1
> > > > > > > 
> > > > > > > This assumes that the detail records were all dated the same day.  
> > > > > > > I am expecting that this is going to come back in a JSON format that  
> > > > > > > I will have to format to look like above.
> > > > > > > 
> > > > > > > Is this what you wanted?
> > > > > > > 
> > > > > > > On Monday, December 15, 2014 1:03:07 PM UTC-5, Sachin Divekar wrote:
> > > > > > > 
> > > > > > > > Hi,
> > > > > > > > 
> > > > > > > > Can you share some sample data and desired output?
> > > > > > > > 
> > > > > > > > Sachin Divekar
> > > > > > > > 
> > > > > > > > On Mon, Dec 15, 2014, 10:00 PM Rod Clayton [rod.c...@gmail.com](mailto:rod.c...@gmail.com)  
> > > > > > > > wrote:
> > > > > > > 
> > > > > > > I have loaded login data into Elasticsearch using Logstash.
> > > > > > > 
> > > > > > > > > I have fields: username retcd workstation.
> > > > > > > > > 
> > > > > > > > > I want to query and get a count of failed logon requests by  
> > > > > > > > > username and workstation on a given day.
> > > > > > > > > 
> > > > > > > > > The indexes are named like logstash-2014.11.18.
> > > > > > > > > 
> > > > > > > > > What would a query for this look like on the day listed above?
> > > > > > > > > 
> > > > > > > > > Thanks,  
> > > > > > > > > Rod
> > > > > > > > > 
> > > > > > > > > --  
> > > > > > > > > You received this message because you are subscribed to the Google  
> > > > > > > > > Groups "elasticsearch" group.
> > > > > > > > 
> > > > > > > > To unsubscribe from this group and stop receiving emails from it,
> > > > > > > > 
> > > > > > > > > send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > > > > > > 
> > > > > > > > > To view this discussion on the web visit  
> > > > > > > > > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e)  
> > > > > > > > > 6-478a-ad77-9418e5822296%[40googlegroups.com](http://40googlegroups.com)  
> > > > > > > > > [https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/dd8ca3ed-c9e6-478a-ad77-9418e5822296%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > > > > > > .  
> > > > > > > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > > > > > > 
> > > > > > > > --  
> > > > > > > > You received this message because you are subscribed to the Google  
> > > > > > > > Groups "elasticsearch" group.  
> > > > > > > > To unsubscribe from this group and stop receiving emails from it,  
> > > > > > > > send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > > > > 
> > > > > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)
> > > > > > 
> > > > > > > msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40goo  
> > > > > > > [glegroups.com](http://glegroups.com)  
> > > > > > > [https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/f6d94667-d81d-40de-a927-de088e2bee69%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > > > > .  
> > > > > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > > > > 
> > > > > > --  
> > > > > > You received this message because you are subscribed to the Google  
> > > > > > Groups "elasticsearch" group.  
> > > > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > > 
> > > > To view this discussion on the web visit [https://groups.google.com/d/ms](https://groups.google.com/d/ms)
> > > > 
> > > > > gid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40goo  
> > > > > [glegroups.com](http://glegroups.com)  
> > > > > [https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/8267fbc1-63cd-400d-a969-5f6191203991%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > > .  
> > > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > > 
> > > > --  
> > > > You received this message because you are subscribed to the Google Groups  
> > > > "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send an  
> > > > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > > > To view this discussion on the web visit  
> > > > [https://groups.google.com/d/msgid/elasticsearch/21cb8c2a-d9bc-497c-a217-bea52dcc2632%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/21cb8c2a-d9bc-497c-a217-bea52dcc2632%40googlegroups.com)  
> > > > [https://groups.google.com/d/msgid/elasticsearch/21cb8c2a-d9bc-497c-a217-bea52dcc2632%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/21cb8c2a-d9bc-497c-a217-bea52dcc2632%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > .  
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/465f5574-1795-4eac-8032-2806695e0b58%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/465f5574-1795-4eac-8032-2806695e0b58%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:43am UTC](https://discuss.elastic.co/t/return-logstash-failed-user-logons-by-day-and-return-code/21260/12 "2017-07-06T00:43:06Z")

</div>


