elastic stack 6.5.1. This question can be applied to any similar query to filter events.
I have visualised users (donut) who have logged in remotely. The inner ring shows users, the outer shows countries. Due to the large number of users, I have two views the the same data, UK and non-UK, but I would like to have one that only shows users who have remotely connected from more than country/city. Of course, this does show users who have multiple coloured outer ring segment, meaning multiple countries.
Hmm - it may be difficult without reorganizing the data. We would need a way to join documents - where usernames match. If we can get all the IP data in the same document then we would have options for creating a flag to filter on.
Without changing the source data, maybe something like a terms aggregation on user and { min_doc_count: 2 } in the Advanced -> JSON Input section may help.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.