I have created a visualization to show the number of netflows per IPV4_SRC_ADDR over time. It is supposed to sort the IP in the legend by Count in descending order. However as you look at the graph below, the IP with pink column occupies most of the flows, but it is at the 13th of the legend while all other IPs with very low flows sit on the top of the legend.
My first thought is that Kibana sorting bases on values in the last column or the overall values in the visualization, but it does not seem to be true.
I've been having issues with those types of graphs where Date Histogram is combined with Bars or Lines, and I am not sure how Kibana actually sorts values.