Kibana Keyword compare and collate based on the unique query list in string format

i have a scenario of collating some list of repeated SQL slow query with date vise transaction. My aim is to achieve unique no of the repeated SLOW query list which occurs in the certain time period in a data table visualization (Group them).

When i add this Query in the Term aggregation with keyword parameter there is no result displayed in the data table.

These are some sample query i want to group,

Any idea if there any custom KQL query can do this job? term agg

Seems like a scripted field can help with that:

The script should pull the information relevant to you out of the message field, then you can use terms on top of it.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.