Watcher Exercise
sudo systemctl start elasticsearch && sudo systemctl start filebeat && sudo systemctl start kibana{ "size": 10, "query": { "bool": { "filter": { "query_string": { "query": "@timestamp:[now-1h TO now]" } } } } }
Last updated
sudo systemctl start elasticsearch && sudo systemctl start filebeat && sudo systemctl start kibana{
"size": 10,
"query": {
"bool": {
"filter": {
"query_string": {
"query": "@timestamp:[now-1h TO now]"
}
}
}
}
}Last updated