Kibana 7.12.0 add Enrich pipeline

I want to calculate the value of a field in index A.

  1. Its data comes from two other index fields, index B and index C.

  2. Calculation formula: index A.count = index B.count - index C.count.

  3. Condition: index A.time = index B.time, index B.time = index C.time.

Can it be achieved? Or any suggestions? :slightly_smiling_face:

What's not clear to me is: Are you speaking of 1 index, or are this multiple indices?


They are multiple indexes.

For this case you would need to build you own custom tool, merging the data and ingesting it into a new index in Elasticsearch

Oh, maybe you could use the ingest pipeline enrich processor for that:

Arithmetic operators do not seem to be supported.

In 7.14 you can achieve this using lens formulas. Any plan to update?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.