如何基于动态主机名与指定ES查询生成可解析Kibana URL
Got it, let's walk through how to create a dynamic Kibana URL that automatically queries the last 15 minutes for whatever hostnames you need. Here's a practical, step-by-step solution:
Kibana lets you encode search parameters directly into URLs, so we'll leverage two core parts of the Discover page URL:
_g: Handles global state (like the time range we care about:now-15mtonow)_aorq: Carries the actual search query (either full Elasticsearch JSON or Kibana's simpler Kuery syntax)
You have two solid options here—pick the one that fits your workflow better:
Option A: Use Kibana's Kuery Syntax (Simpler)
Kuery is Kibana's user-friendly query language, which translates cleanly to Elasticsearch under the hood. For your use case, the Kuery would look like:
(beat.hostname.raw: "host1" OR beat.hostname.raw: "host2") AND @timestamp >= now-15m
We'll URL-encode this string and plug it into the q parameter of the Kibana URL.
Option B: Use Raw Elasticsearch JSON (Exact Match to Your Original Query)
If you want to stick exactly to the bool query you provided, we can encode that full JSON into the URL's _a parameter. Your base query (with dynamic host slots) looks like:
{ "query": { "bool": { "minimum_should_match": 1, "should": [{"match": {"beat.hostname.raw": "HOST_PLACEHOLDER"}}], "must": [{"range": {"@timestamp": {"gte": "now-15m", "lte": "now"}}}] } } }
Use a script to take your list of hostnames, build the query, encode it, and spit out a ready-to-use Kibana URL. Here are examples for two common tools:
Example 1: Python Script
This script takes your Kibana base URL, index pattern, and hostnames as inputs, then generates the full URL using Kuery (easier to maintain):
import urllib.parse def build_kibana_url(kibana_base, index_pattern, hostnames): # Build the Kuery string from hostnames host_clauses = [f'beat.hostname.raw: "{host}"' for host in hostnames] kuery = f"({' OR '.join(host_clauses)}) AND @timestamp >= now-15m" # URL-encode the query encoded_kuery = urllib.parse.quote(kuery) # Assemble the full URL return ( f"{kibana_base}/app/discover#/?" f"_g=(time:(from:'now-15m',to:'now'))" f"&q={encoded_kuery}" f"&index={index_pattern}" ) # Usage example kibana_url = build_kibana_url( "http://your-kibana:5601", "filebeat-*", # Replace with your index pattern ["host1.example.com", "host2.example.com"] ) print(kibana_url)
Example 2: Bash Script
If you prefer a shell script for quick command-line use:
#!/bin/bash # Configure these values first KIBANA_BASE="http://your-kibana:5601" INDEX_PATTERN="filebeat-*" # Build the host clauses HOST_CLAUSES="" for host in "$@"; do if [[ -z "$HOST_CLAUSES" ]]; then HOST_CLAUSES="beat.hostname.raw: \"$host\"" else HOST_CLAUSES="$HOST_CLAUSES OR beat.hostname.raw: \"$host\"" fi done # Build and encode Kuery KUERY="($HOST_CLAUSES) AND @timestamp >= now-15m" ENCODED_KUERY=$(echo "$KUERY" | python3 -c "import urllib.parse; print(urllib.parse.quote(input()))") # Generate final URL FULL_URL="${KIBANA_BASE}/app/discover#/?_g=(time:(from:'now-15m',to:'now'))&q=${ENCODED_KUERY}&index=${INDEX_PATTERN}" echo "Generated Kibana URL:" echo "$FULL_URL"
Run it like: ./generate-kibana-url.sh host1 host2 host3
- Replace
http://your-kibana:5601with your actual Kibana instance URL - Update
filebeat-*to match your Beat index pattern (e.g.,metricbeat-*) - Ensure the time range in the
_gparameter matches your query (now-15mhere)—this prevents Kibana from overriding your query's time filter - If you use the JSON query approach, double-check the
_aparameter structure by manually creating a search in Kibana, copying the URL, and adapting it (Kibana versions can tweak this structure slightly)
内容的提问来源于stack exchange,提问作者deez

