Hi there! I’m trying to create an “area stacked” visualization that shows event.dataset over the last 90 days. Is there a way to group the endpoint.events.network, endpoint.events.process, and events.events.file logs into one item so when showing the top five log sources, it would be one line rather than three of the five?
You can see in the screenshot below, having endpoint.events.* be 60% of the log sources. rather than 20% leaves little room for other important log sources.
Thanks!


