I am struggeling with a little aggregation task. Let's say we have to following data from winlogbeat:
First data:
{
"param1": "1.2.3.4:5555"
}
Second data:
{
"param1": "1.2.3.4:6666"
}
If I perform a pie chart with count it will tell me 1.2.3.4:6666 and 1.2.3.4:5555 separately. How am I able to perform a count on everything before the :. I do not care about the ports.
I am not able to rework the pipeline or todo something inside winlogbeat. Therefore, I have to solve this issue inside kibana.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.