I am using the EFK stack at work. Mo one seems to know much about it.
I struggled to get script fields working in kibana due to my field not being aggregatable I believe. I couldn't really figure out how to change the field to be aggregatable using dev tools. The person I am reporting to does not want to alter fluentd which I think is likely the best option to parse with, correct me if I am incorrect.
What can I do with elasticsearch? Can I parse fields from there. I have a better chance of gaining access to ES config files than I do fluentd files.
this message field is what I am trying to parse. I want the time field parsed into a numeric field.
message: words::words::words (time=517, words)