Create script-field and aggregate+filter+bucket on that

(ddorian43) #1


I have a complex _uid, which can be used in aggregations.

The _uid is like:


Is it possible to use a script (or something else), so I move each "var(x)" into a separate field, and use them for filtering, aggregating (top "var1" values), basically just use them like you would use a normal field.

Thank You

(Yannick Welsch) #2

Extracting data from one field into other fields at index time will be made possible by the upcoming ingest functionality (see ). An index-time alternative is to use Logstash.
The simplest solution might just be to properly index the information that is now contained in the _uid field.

(ddorian43) #3

I don't need for index-time, I needed for query-time, to lower the storage and duplicate indexes.

(system) #4