Mutiline parsing using IngestNode pipelines

Hello,
I am using filebeat along with Ingest node pipelines to create index data.
My indexed data looks like below screenshot.


From the screenshot , i need to count number of ACT_REJ after ACT_REQ.
Basically my use case is to calculate the number of rejections that has happened after the activation request has been sent.
Can someone please provide any ideas or suggestions on how to implement this ?
Either a datatable or Barchart is what i am looking for .

I am looking for some ideas from Elastic Team.. :frowning:

Any ideas ??!! :frowning: :frowning:

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.