Kibana 4.1 export search results

We recently moved our centralized magazine from Splunk to an ELK solution, and we need to export search results - is there any way to do this in Kibana 4.1? If there is, this is not entirely obvious ...

Thanks!

+9
source share
5 answers

Of course, you can export from Kibana Discover (Kibana 4.x +). 1. On the search page, click the up arrow here: enter image description here

  1. Now, at the bottom of the page, you have two options for exporting search results.

enter image description here

At logz.io (the company I work for), we will send out scheduled reports based on specific searches.

-7
source

If you want to export logs (and not just the timestamp and quantity), you have a couple of options (tylerjl answered this question very well on the Kibana forums ):

If you want to export logs from Elasticsearch, you probably want to save them somewhere, so viewing them in a browser is probably not the best way to view hundreds or thousands of logs. There are several options here:

  • On the Discovery tab, you can click the tab with the arrows below to see the raw request and response. You can click "Request", and use this as a request to ES with a curl (or something similar) with request ES for the required logs.

  • You can use logstash or stream2es206 to upload the contents of the index (with possible query parameters to get the specific documents you want.)

+8
source

If you have problems with your own query using curl or don’t need an automatic program for extracting logs from Kibana, just click "Reply" and get what you need.

After problems such as the β€œlack of xsrf token” when using curl, I found this method simpler and simpler!

As others have said, the "Request" button appears after clicking the tab with the arrow below.

request button

+1
source

This is a very old post. But I think that someone is still looking for a good answer.

You can easily export search results from Kibana Discover.

First click Save , then click Share

Click ** Save ** first, then click ** Share **

Click CSV Reports

Click CSV Reports

Then click Create CSV

Then click ** Generate CSV **

After a few seconds, you will get the download option at the bottom right.

+1
source

Only the timestamp and the number of messages at that time are exported, not the log information:

Raw Material:

1441240200000,1214 1441251000000,1217 1441261800000,1342 1441272600000,1452 1441283400000,1396 1441294200000,1332 1441305000000,1332 1441315800000,1334 1441326600000,1337 1441337400000,1215 1441348200000,12523 14413590000

formatted:

"September 3, 2015, 06: 00: 00.000", "1,214", "September 3, 2015, 09: 00: 00.000", "1,217", "September 3, 2015, 12: 00: 00 000", "1 342 "," September 3, 2015, 15: 00: 00.000 "," 1,452 "," September 3, 2015, 18: 00: 00.000 "," 1 396 "," September 3, 2015, 21: 00: 00 000 "," 1,332 "," September 4, 2015, 00: 00: 00.000 "," 1,332 "," September 4, 2015, 03: 00: 00.000 "," 1,334 "," September 4, 2015, 06: 00: 00.000 "," 1337 "," September 4, 2015, 09: 00: 00.000 "," 1,215 "," September 4, 2015, 12: 00: 00 000 "," 12 523 "," September 4, 2015, 15 : 00: 00.000 "," 61 897 "

0
source

All Articles