Sql in elasticsearch/kibana

(Lynn) #1

We have a logstash file with documents like:

2018-11-22 07:23:44,374 :: HWM :: INFO :: ########## Service Status: {'weight': True, 'main_cam': True, 'bp': True, 'scanner': True, 'oto_nose': True, 'thermo': True, 'ox': True, 'oto_ear': True, 'oto_mouth': True}
November 22nd 2018, 07:23:44.374
We need to do things like select all docs where main_cam="False" . Basically queries of sub-queries of sub-queries. Users at our organization are familiar with SQL and would like to use it, as opposed to learning a new language. What is the best study/learning document you can suggest?

(Mark Walkom) #2

You really need to split the message contents into their own fields using grok first.

(Lynn) #3

Will do. THANK YOU!

(system) closed #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.