Hi All, I have some raw message have been parsed with below fields:
Kibana index name begins with logstash-xxx.
The question is now I am using Kibana 4.5.0 and visualize my data with Metric and Data Table. I can easily filtered my data with EventID say 676 and shows total counts in Metric is correct. But the question is that it has a wrong count show in Data Table. An example is just like below:
Enable Filter: EventID:676
1141 <-- This is correct number of entries.
EveintID.raw Message.raw Count
676 Some message 323 <-- (only 323 showed but total count is 1141)
I have tried not to use Message.raw field and it shows correct count 1141. I tried to review the log in Discovery view, it show that was parsed successfully in message field. Seems parsing has no problem but the data view exist missing counts in Data Table.
Thank you in advance for your help with this!