Splunk-like query results in Kibana?

(ZillaG) #1

I have not personally used splunk, but I'm told that it has a feature where if one performs a log search and gets a hit, splunk will show N logs before and N logs after the query result. Can I do the same in Kibana? If so how? I have the ELK stack. Thanks!

(Brandon Kobel) #2

@ZillaG we're actively working on adding support for this, but it's not currently available.

(Chris Weed) #3

We've built a "raw log viewer" type of plugin that is planned on doing similar.

If you are feeling ambitious you could build out the plugin to do this pretty quickly. Lots of copy/paste from the Discover plugin then when a user clicks a result (or a button near the result) just focus the results to a time period based on that item. Of course this assumes time based logs, not just documents.

(Brandon Kobel) #4

Some exciting progress has been made on this, if either of you are interested in tracking the progress on GitHub, here's the work-in-progress pull request https://github.com/elastic/kibana/pull/9198

(ZillaG) #5


(system) #6

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.