Sorry for the delay, and thank you for your answer.
My results are like this in discovery when I click on rules :
["RULE","888821"]
["OTHER_RULE","888822"]
So I think you're right, it's a dual mapping.
But how can I tell to kibana when I want to make my visualization, to do not use the first field (here "RULE" "OTHER_RULE" etc) ?
You might be able to construct a scripted field to access the value you want using painless scripting. I'm not sure I can provide an exact script for you to try, but that approach would give you more control over the value.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.