Hi, I can't make visualisation table using a field I add from logstash.
In logstash conf file used, I read a log file containing XML data.
XML data example :
<root_doc> ... <Body> <Source> <tag> <Header Version="x" SentAt="date" To="to" /> ... </tag> </Source> </Body> </root_doc>
I add fields into elasticsearch like this
xpath => ["//Header/@Version" , "Version"] xpath => ["//Header/@SentAt" , "SentAt"] xpath => ["//Header/@To" , "To"] xpath => ["//Source/*" , "XMLOrigine"]
So, fields Version, SentAt, To, XMLOrigine are created, Version.keyword, SentAt.keyword, To.keyword and XMLOrigine.keyword too.
They are all string.
But only the XMLOrigine.keyword field is not searcheable and aggregatable.
Can someone explain me why and how can I transform the XMLOrigine.keyword searchable and aggregatable.