In Kibana 4 I had simple bar charts that showed on the X-Axis the time and on the Y-Axis I had a Split Bar, Sub Aggreation Terms, Field Hostname.raw and then it showed me the Top5 according to my saved search.
In Kibana 5 this doesn't work anymore. The setup is now:
Sub Aggregation: Terms
Field: Hostname: raw
Order by: metric Count
Order: Descending: 5
But it doesn't split the bar up into the hostnames but shows only bars with a count which seems to be aggregated over the top 5 hostnames I guess. When I enable aggregation I get no results, with disabled aggregation I get the bars with the count.
The only way I see to get the bars back like in Kibana 4 is using now filters and add a filter by hand for each and every host. But this also means that I have to change my visualizations each time I add a host to my environment which is cumbersome.
How do I get the behavior from Kibana 4 back?