I have documents coming into elasticsearch that have a host field (string) and an update timestamp (string). I want to show a table of all unique hosts with their last update time.
I created a data table visualization and used "Top Hit" with the update time field and for the buckets I split rows based on host. For the Top Hit, when I concatenate with 1, all the update times for all hosts are blank except the last document that came in.... but I want the last time for each particular host.
So then I changed the concatenate to 100 and it shows long lists for each hosts with a blank for every document that comes in but it eventually shows the update time if it was in the last 100.
What's going on? How do I just show the last update time for each particular host?