# View only last logline from all hosts

**URL:** <https://discuss.elastic.co/t/view-only-last-logline-from-all-hosts/238206>\
**Category:** Kibana\
**Created:** [June 23, 2020, 7:25am UTC](https://discuss.elastic.co/t/view-only-last-logline-from-all-hosts/238206 "2020-06-23T07:25:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcel27](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcel27/32/78264_2.png) [@Marcel27](https://discuss.elastic.co/u/Marcel27)\
**Post date:** [June 23, 2020, 7:25am UTC](https://discuss.elastic.co/t/view-only-last-logline-from-all-hosts/238206/1 "2020-06-23T07:25:45Z")

</div>

For a specific use case where i have 1000+ hosts using filebeat to send a logfile to ES,  
i want a view in Kibana with a (filterable) listview of all hosts, with only the last logline of each host.  
Is this possible, and if so, can you give me some directions how to implement this ?

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [June 24, 2020, 4:00pm UTC](https://discuss.elastic.co/t/view-only-last-logline-from-all-hosts/238206/2 "2020-06-24T16:00:57Z")

</div>

Hello @Marcel27 -

Hopefully this is helpful - [Is it possible to return only the most recent of 'each document'?](https://discuss.elastic.co/t/is-it-possible-to-return-only-the-most-recent-of-each-document/172011)

---

<div class="post-metadata">

**Author:** ![Marcel27](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcel27/32/78264_2.png) [@Marcel27](https://discuss.elastic.co/u/Marcel27)\
**Post date:** [June 26, 2020, 2:32pm UTC](https://discuss.elastic.co/t/view-only-last-logline-from-all-hosts/238206/3 "2020-06-26T14:32:10Z")

</div>

thanks, but 2 questions arise:

1: Whatever field i use for collapse (fe. host.name) i get :  
"reason": "no mapping found for `hostname` in order to collapse on"  
Which fields can i collapse on ?

fe: GET /cmndmetrics/\_mapping/field/host.name returns :

```auto
    {
      "cmndmetrics" : {
        "mappings" : {
          "host.name" : {
            "full_name" : "host.name",
            "mapping" : {
              "name" : {
                "type" : "text",
                "fields" : {
                  "keyword" : {
                    "type" : "keyword",
                    "ignore_above" : 256
                  }
                }
              }
            }
          }
        }
      }
    }

```

but:

```auto
    GET cmndmetrics/_search
    {
      "size": 1, 
      "query": {
        "match_all": {}
      },
      "collapse": {
        "field": "host.name"
      }
    }

```

```
returns error with:

```

```auto
            "reason": {
              "type": "search_context_exception",
              "reason": "unknown type for collapse field `host.name`, only keywords and numbers are accepted"
            }

```

2: When i get above working in "Dev Tools", i get (long) Json struct.  
How can i use this query output to show a listview of all hosts (one line per host) ?  
I think i have to be somewhere else than "dev tools" for this ?

---

<div class="post-metadata">

**Author:** ![Marcel27](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcel27/32/78264_2.png) [@Marcel27](https://discuss.elastic.co/u/Marcel27)\
**Post date:** [June 27, 2020, 9:26am UTC](https://discuss.elastic.co/t/view-only-last-logline-from-all-hosts/238206/4 "2020-06-27T09:26:57Z")

</div>

I realize that what i am trying to achieve may be called custom "metrics".  
I have an application which produces a logfile like:

```
{"field1": 21, "field2": 45, "utctime": "2020-06-26 13:48:36,", "event": "test1"}
{"field1": 62, "field2": 15, "utctime": "2020-06-26 13:53:36,", "event": "test2"}
{"field1": 12, "field2": 14, "utctime": "2020-06-26 13:58:36,", "event": "test3"}

```

In Kibana i want a listview with latest values like:

```
 hostname field1 field2 
 hostname1 12 14   
 hostname2 24 34   

```

Do i have to write a metricbeat module for his (seems much work for simple requirement like this)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2020, 9:27am UTC](https://discuss.elastic.co/t/view-only-last-logline-from-all-hosts/238206/5 "2020-07-25T09:27:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
