I'm using Kibana 5.0 for visualizing Windows Event Logs like the following:
My Problem is, that there are two Logon ID's and Kibana is using the first one to be a field, but I need the second one for filtering. What can I do? Do I have to change the mapping in ElasticSearch? I'm new to the ELK-Stack. =)
Thanks in advance!