elastiflow使用ElasticSearch搜索统计不同源地址和目标地址

源地址

GET elastiflow-3.4.1-*/_search
{
"_source": {
    "includes": [
      "flow.src_addr"   //返回的字段
    ],
    "excludes": []
  },
  "aggs": {
    "uniq_attr": {
      "cardinality": {
        "field": "flow.src_addr"
      }
    }
  }
}

目标地址

GET elastiflow-3.4.1-*/_search
{
"_source": {
    "includes": [
      "flow.dst_addr"   //返回的字段
    ],
    "excludes": []
  },
  "aggs": {
    "uniq_attr": {
      "cardinality": {
        "field": "flow.dst_addr"
      }
    }
  }
}

猜你喜欢

转载自blog.csdn.net/allway2/article/details/109182241