查詢最近一小時內data.@level字段為Error的日志並按date倒序排列,輸出最近10條,只輸出[date,message]兩個字段
GET events*/_search
{
"query"
: {
"bool"
: {
"must"
: [
{
"query_string"
: {
"fields"
: [
"data.@level"
],
"query"
:
"Error"
}
}
],
"filter"
: {
"range"
: {
"date"
: {
"gte"
:
"now-1h"
,
"lte"
:
"now"
}
}
}
}
},
"sort"
: [
{
"date"
: {
"order"
:
"desc"
,
"missing"
:
"_last"
}
}],
"_source"
: [
"date"
,
"message"
],
"size"
: 10
}
|