I am creating a couple of bar-charts from Logstash-data and I do a split chart to differentiate a couple of servers. I do that by using a sub aggregation "Terms" and use the field hostname.raw.
Now I see for several servers that they appear twice in the chart as the following:
Is there a way to combine them when splitting them automatically by Hostname.raw? I could use host.raw but that gives me an IP-addressand I'd really prefer DNS-names.