You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何基于动态主机名与指定ES查询生成可解析Kibana URL

Got it, let's walk through how to create a dynamic Kibana URL that automatically queries the last 15 minutes for whatever hostnames you need. Here's a practical, step-by-step solution:

Step 1: Understand Kibana's URL Basics

Kibana lets you encode search parameters directly into URLs, so we'll leverage two core parts of the Discover page URL:

  • _g: Handles global state (like the time range we care about: now-15m to now)
  • _a or q: Carries the actual search query (either full Elasticsearch JSON or Kibana's simpler Kuery syntax)
Step 2: Pick Your Query Format

You have two solid options here—pick the one that fits your workflow better:

Option A: Use Kibana's Kuery Syntax (Simpler)

Kuery is Kibana's user-friendly query language, which translates cleanly to Elasticsearch under the hood. For your use case, the Kuery would look like:

(beat.hostname.raw: "host1" OR beat.hostname.raw: "host2") AND @timestamp >= now-15m

We'll URL-encode this string and plug it into the q parameter of the Kibana URL.

Option B: Use Raw Elasticsearch JSON (Exact Match to Your Original Query)

If you want to stick exactly to the bool query you provided, we can encode that full JSON into the URL's _a parameter. Your base query (with dynamic host slots) looks like:

{
  "query": {
    "bool": {
      "minimum_should_match": 1,
      "should": [{"match": {"beat.hostname.raw": "HOST_PLACEHOLDER"}}],
      "must": [{"range": {"@timestamp": {"gte": "now-15m", "lte": "now"}}}]
    }
  }
}
Step 3: Implement Dynamic Hostname Replacement

Use a script to take your list of hostnames, build the query, encode it, and spit out a ready-to-use Kibana URL. Here are examples for two common tools:

Example 1: Python Script

This script takes your Kibana base URL, index pattern, and hostnames as inputs, then generates the full URL using Kuery (easier to maintain):

import urllib.parse

def build_kibana_url(kibana_base, index_pattern, hostnames):
    # Build the Kuery string from hostnames
    host_clauses = [f'beat.hostname.raw: "{host}"' for host in hostnames]
    kuery = f"({' OR '.join(host_clauses)}) AND @timestamp >= now-15m"
    
    # URL-encode the query
    encoded_kuery = urllib.parse.quote(kuery)
    
    # Assemble the full URL
    return (
        f"{kibana_base}/app/discover#/?"
        f"_g=(time:(from:'now-15m',to:'now'))"
        f"&q={encoded_kuery}"
        f"&index={index_pattern}"
    )

# Usage example
kibana_url = build_kibana_url(
    "http://your-kibana:5601",
    "filebeat-*",  # Replace with your index pattern
    ["host1.example.com", "host2.example.com"]
)
print(kibana_url)

Example 2: Bash Script

If you prefer a shell script for quick command-line use:

#!/bin/bash

# Configure these values first
KIBANA_BASE="http://your-kibana:5601"
INDEX_PATTERN="filebeat-*"

# Build the host clauses
HOST_CLAUSES=""
for host in "$@"; do
    if [[ -z "$HOST_CLAUSES" ]]; then
        HOST_CLAUSES="beat.hostname.raw: \"$host\""
    else
        HOST_CLAUSES="$HOST_CLAUSES OR beat.hostname.raw: \"$host\""
    fi
done

# Build and encode Kuery
KUERY="($HOST_CLAUSES) AND @timestamp >= now-15m"
ENCODED_KUERY=$(echo "$KUERY" | python3 -c "import urllib.parse; print(urllib.parse.quote(input()))")

# Generate final URL
FULL_URL="${KIBANA_BASE}/app/discover#/?_g=(time:(from:'now-15m',to:'now'))&q=${ENCODED_KUERY}&index=${INDEX_PATTERN}"

echo "Generated Kibana URL:"
echo "$FULL_URL"

Run it like: ./generate-kibana-url.sh host1 host2 host3

Key Notes to Avoid Headaches
  • Replace http://your-kibana:5601 with your actual Kibana instance URL
  • Update filebeat-* to match your Beat index pattern (e.g., metricbeat-*)
  • Ensure the time range in the _g parameter matches your query (now-15m here)—this prevents Kibana from overriding your query's time filter
  • If you use the JSON query approach, double-check the _a parameter structure by manually creating a search in Kibana, copying the URL, and adapting it (Kibana versions can tweak this structure slightly)

内容的提问来源于stack exchange,提问作者deez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:37:52