Hello there, I am using ELK6.4 stack, I have data like the attached picture, and the search works only if I give like this "headers.direction:external" , but i need it to work when i give "direction:external", I am searching from Kibana.Please advice.
The search looks at the field name. so it seems you like to change the headers.direction field to be renamed as direction. You'll likely want to index your documents with the correct fieldname direction.
thanks thomas, I can not upate the index, as it is being used by many other applications, Can I update the elastic template to somehow search direction:value , when headers.direction:value is used ?, like a pattern saying , when headers.* is searched , either strip "headers" from the query, or go look under headers.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.