How to increase the options in "Terms" to create graphics in Kibana


(Hendrick Lonck) #1

Hi for all.

I have servers that send log to the Elastic Stack with use of filebeat.

I'm having trouble creating charts in Kibana why are displayed few options to Terms. Only are displayed syslog options, but none of the apache.

Any suggestions to increase search options?

Thanks.


(Thomas Neirynck) #2

hi @Lonck,

Could you explain a little more?

Are you not seeing your index-patterns and fields in the Visualize Data panel?


(Hendrick Lonck) #3

Hi Thomas!

Thank you for your replay.

I saearched for the solution and found what I need.
I beleave that the options for chats creating are offered by "significant terms aggregation"
I want to create charts using terms like geoip.region_name.raw, useragent.os_name.raw or useragent.name.raw (see example: https://www.youtube.com/watch?v=Cjww_oug2E8)
You would have any example for configuring the significant terms aggregation in Elasticsearch?

Thanks.


(Thomas Neirynck) #4

The significant terms is a very unique aggregator. You can read an intro here: https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-significantterms-aggregation.html. Basically, it allows you to identify significant occurrences of one or more terms in a subset of documents, compared to the entire collection.

If you just want to aggregate on some field-value (e.g. compute some metrics for each unique field-value), you'll want to use the "Terms"-aggregation instead.


(Hendrick Lonck) #5

Hi Thomas!
Thank you very much for your explanation.
I studied about Terms Aggregation to achieve the goal.


(Hendrick Lonck) #6

Hi Thomas!
I found explanation about terms aggregation in https://www.elastic.co/guide/en/elasticsearch/reference/5.0/search-aggregations-bucket-terms-aggregation.html, However I did not understand where to enter these commands. Could you give an example?

Thanks.


(Hendrick Lonck) #7

Hi for all!
Any suggestion of graphical interface for Elasticsearch management?
I want to create Terms Aggregations expressions to generate charts in Kibana.
Thanks.


(system) #8