Combine fields in the Kibana visualization


I have some indices with following fields

status: ["Failed", "Succeeded", "None"]
user_id:  user_id

I want to add events with status None to Failed if they are not in Succeeded set. This can be checked by user_id. So I need to collect all user_ids for status=Succeeded and if the user_id of a None is not in that set, I have to add it to Failed set. How can I achieve this by using advanced option (json inout) in the visualization?

Hello, this is not something that is doable in Elasticsearch by default, it's something that works in a tabular database instead of document one.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.