As you can see in the first data set, the same status events appear multiple times. Here I'd like to visualize them with only the first status event instead of all. Perhaps I should use Logstash, but not at this time for some reason. Do you have any good ideas?
Thank you so much for the response. Let me have a little more clues.
Would you mind writing a rough JSON example for the query? I've read the top_hit doc through, and it seems good but not perfect since it targets data to be aggregated by field value. In contrast, my data can continue across days, months, or years and should be aggregated by "consecutiveness".
Is it possible for me to express the output in Kibana visualization? I've checked "Metrics" in Kibana can hold the top_hit aggregation, but still not sure exactly how to.
Would you please correct me if I'm wrong? I need to learn more
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.