Skip to content

Instantly share code, notes, and snippets.

@jmelloy
Last active December 25, 2015 02:58
Show Gist options
  • Save jmelloy/6905914 to your computer and use it in GitHub Desktop.
Save jmelloy/6905914 to your computer and use it in GitHub Desktop.
>>> d = qe.logstash_query('@fields.hostname:"SEADCWEB10.hq.apfm.local"', "@fields.EventTime,@fields.request")
>>> len(d["rows"])
1100
>>> d["rows"] = len(d["rows"])
>>> d
{'query': '{"sort": {"@timestamp": {"order": "desc"}}, "fields": ["@fields.EventTime", "@fields.request"],
"size": 50,
"from": 1050,
"query": {"filtered": {"filter":
{"range": {"@timestamp": {"to": "2013-10-09T18:23:46.851697", "from": "2013-10-09T18:08:46.851697"}}},
"query": {"query_string": {"query": "@fields.hostname:\\"SEADCWEB10.hq.apfm.local\\"", "default_operator": "OR", "default_field": "_all"}}}}}',
'start_time': datetime.datetime(2013, 10, 9, 18, 23, 47, 273138),
'rows': 1100, 'run_time': 0.0070000000000000001, 'columns': ['EventTime', 'request']}
>>> qe.logstash_query('"SEADCWEB10"', "@fields.EventTime,@fields.request")
{'query': '{"sort": {"@timestamp": {"order": "desc"}}, "fields": ["@fields.EventTime", "@fields.request"],
"size": 50, "from": 0,
"query": {"filtered": {"filter": {
"range": {"@timestamp": {"to": "2013-10-09T18:25:08.644734", "from": "2013-10-09T18:10:08.644734"}}},
"query": {"query_string": {"query": "\\"SEADCWEB10\\"", "default_operator": "OR", "default_field": "_all"}}}}}',
'start_time': datetime.datetime(2013, 10, 9, 18, 25, 8, 654907), 'rows': [],
'run_time': 0.0070000000000000001, 'columns': ['EventTime', 'request']}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment