We have log in json format with nested json object.
I seems that "nested" field are shown in the field list in settings dunt not in the left bar under discover section. Look the image below, the warning message says Analysis is not available for object field..
Let me make a correction. Can you go to your Settings tab, select your index pattern, and click the "refresh field list" and then look for you nested fields there? It helps to sort by name, and then look for evento, and something like evento.ip, etc.
Hi Lee I can see all "subfield" of event, and use them in aggregation.
But I can't see them in the left side of discover tab (where Fields are listed) (see screeshot above).
Kibana only shows the analyzed fields on the Discover tab because are most commonly used for filtering and the list might be too long otherwise. But you can still use the subfields in the query bar. You just have to know what they are from the Settings tab list of fields.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.