如何用Kibana-Elastic编写查询获取特定月份每小时峰值流量
Get Hourly Peak Traffic for a Specific Month in Elasticsearch/Kibana
Got it, let's break down how to pull the hourly peak traffic for your target month. I'll walk you through a complete query and explain each part so you can adapt it to your dataset easily.
Core Query Structure
Here's a ready-to-use Elasticsearch DSL query you can run directly in Kibana's Dev Tools. I'm using common field names like @timestamp (standard for time-series data) and traffic_volume for the metric—swap these out for your actual field names:
GET /your-target-index/_search { "size": 0, // Skip raw document results, we only need aggregated data "query": { "bool": { "filter": [ { "range": { "@timestamp": { "gte": "2024-05-01T00:00:00.000Z", // Start of your target month (ISO 8601 format) "lte": "2024-05-31T23:59:59.999Z" // End of your target month } } } ] } }, "aggs": { "hourly_time_buckets": { "date_histogram": { "field": "@timestamp", "calendar_interval": "hour", // Split data into consistent hourly buckets "time_zone": "UTC" // Adjust to your local timezone if needed, e.g., "Asia/Shanghai" }, "aggs": { "peak_hourly_traffic": { "max": { "field": "traffic_volume" // Replace with your actual traffic metric field } } } } } }
Key Parts Explained
size: 0: Turns off raw document returns since we only care about the aggregated peak values.- Range Filter: Pinpoints exactly your target month—update the
gteandltedates to match the month you're working with (stick to ISO 8601 format for reliability). date_histogramAggregation: Groups your data into hourly buckets. Usingcalendar_interval: "hour"ensures accurate hourly splits, even if your data spans daylight saving time changes (just set the correcttime_zone).maxSub-Aggregation: Calculates the highest traffic value within each hourly bucket—this is your hourly peak traffic.
Using This in Kibana
- Dev Tools: Paste the query, swap in your index name and field names, then click "Run". The results will show up under the
aggregationssection, with each hourly bucket and its corresponding peak traffic. - Visualization: To turn this into a chart, create a new "Line Chart" visualization. Set the X-axis to a
Date Histogramwith interval "Hour", add aMaxmetric for your traffic field, and apply the same date range filter for your target month.
Quick Tips
- Double-check field names: Make sure
your-target-index,@timestamp, andtraffic_volumematch the actual names in your Elasticsearch index. - Timezone adjustment: If your traffic data is recorded in a non-UTC timezone, update the
time_zoneparameter to avoid off-by-one-hour errors. - Date format: If your date field uses a non-ISO format, adjust the range filter values to match your data's date structure.
内容的提问来源于stack exchange,提问作者Anila Liaqat
相关产品推荐
相关产品推荐

