结构如下
我想统计出前10名的sourceIp对应的rcvBytes值的和在特定的timestamp内
请问有相关的DSL语句例子吗?感觉DSL超级难写!
{
"mapping": {
"usgtrafficlog": {
"properties": {
"closeReason": {
"type": "keyword"
},
"destinationIp": {
"type": "keyword"
},
"destinationPort": {
"type": "long"
},
"protocol": {
"type": "keyword"
},
"rcvBytes": {
"type": "long"
},
"securityPolicyName": {
"type": "keyword"
},
"sendBytes": {
"type": "long"
},
"sourceIp": {
"type": "keyword"
},
"sourceNATIp": {
"type": "keyword"
},
"sourceNATPort": {
"type": "long"
},
"sourcePort": {
"type": "long"
},
"timestamp": {
"type": "long"
}
}
}
}
}
我想统计出前10名的sourceIp对应的rcvBytes值的和在特定的timestamp内
请问有相关的DSL语句例子吗?感觉DSL超级难写!
3 个回复
rochy - rochy_he
赞同来自: elasticStack
hel2o
赞同来自:
cl1321 - 85后IT女
赞同来自:
参考: How to use scripts