How to visualize difference between two fields


I have 'setcount' and 'clearedcount' number fields which i added in logstash when it finds "set" in message field setcount is set to 1 and if it finds "clear" in message filed it sets clearedcount to 1.

each event will have either setcount or clearedcount.

I wanted to visualize something like setcount - clearedcount per host.

How can i acheive this in visualization.

Hi Pola,

You can use a scripted field here. Here is where you will add it:

Once you do you can use any basic chart to do your aggregation on it.



Thanks bhavyarm! I ended up in doing the same thing and it worked. Thanks for sharing.

