Hi Team,
First I want to thank you all for such an awesome product.
I wanted to evaluate Elasticsearch and Splunk features. I had few queries in this regard and this is my first post to the Forum:
-
I was wondering whether Elasticsearch/Kibana offers anything similar to PIPE in Queries where we can use output of first query as a input for another.
-
Also Is it possible to create fields on the fly?
e.g. let us say I parsed 3-4 fields and one additional message field. Now from message field I want to extract another new field and want to create graphs etc. on this new field. -
Can we create charts through queries using pipe as possible in Splunk?
Also I would like to know in case any of these things are planned.
Thanks