My data have following columns:
- MAC (keyword) - mac of device
- errors (integer) - errors in record on device
- switch (keyword) - switch connected to device
Schema is denormalized for fast search purposes.
In 30 minutes I have 6 data records from each device with unique MAC.
I'd like to build report: "Show switches with max count of broken devices" or
"Show all switches with number of broken devices > 3"
Device is broken when: each its data record (by MAC) has errors > 0.
Is it possible to build report like this by Kibana visualization or timelion?
ES API query is also appropriate solution.