You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Kibana-Elastic编写查询获取特定月份每小时峰值流量

Get Hourly Peak Traffic for a Specific Month in Elasticsearch/Kibana

Got it, let's break down how to pull the hourly peak traffic for your target month. I'll walk you through a complete query and explain each part so you can adapt it to your dataset easily.

Core Query Structure

Here's a ready-to-use Elasticsearch DSL query you can run directly in Kibana's Dev Tools. I'm using common field names like @timestamp (standard for time-series data) and traffic_volume for the metric—swap these out for your actual field names:

GET /your-target-index/_search
{
  "size": 0, // Skip raw document results, we only need aggregated data
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "2024-05-01T00:00:00.000Z", // Start of your target month (ISO 8601 format)
              "lte": "2024-05-31T23:59:59.999Z"  // End of your target month
            }
          }
        }
      ]
    }
  },
  "aggs": {
    "hourly_time_buckets": {
      "date_histogram": {
        "field": "@timestamp",
        "calendar_interval": "hour", // Split data into consistent hourly buckets
        "time_zone": "UTC" // Adjust to your local timezone if needed, e.g., "Asia/Shanghai"
      },
      "aggs": {
        "peak_hourly_traffic": {
          "max": {
            "field": "traffic_volume" // Replace with your actual traffic metric field
          }
        }
      }
    }
  }
}

Key Parts Explained

  • size: 0: Turns off raw document returns since we only care about the aggregated peak values.
  • Range Filter: Pinpoints exactly your target month—update the gte and lte dates to match the month you're working with (stick to ISO 8601 format for reliability).
  • date_histogram Aggregation: Groups your data into hourly buckets. Using calendar_interval: "hour" ensures accurate hourly splits, even if your data spans daylight saving time changes (just set the correct time_zone).
  • max Sub-Aggregation: Calculates the highest traffic value within each hourly bucket—this is your hourly peak traffic.

Using This in Kibana

  • Dev Tools: Paste the query, swap in your index name and field names, then click "Run". The results will show up under the aggregations section, with each hourly bucket and its corresponding peak traffic.
  • Visualization: To turn this into a chart, create a new "Line Chart" visualization. Set the X-axis to a Date Histogram with interval "Hour", add a Max metric for your traffic field, and apply the same date range filter for your target month.

Quick Tips

  • Double-check field names: Make sure your-target-index, @timestamp, and traffic_volume match the actual names in your Elasticsearch index.
  • Timezone adjustment: If your traffic data is recorded in a non-UTC timezone, update the time_zone parameter to avoid off-by-one-hour errors.
  • Date format: If your date field uses a non-ISO format, adjust the range filter values to match your data's date structure.

内容的提问来源于stack exchange,提问作者Anila Liaqat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:04:40