In visualization, it is possible to hard code known values into filters
which then work as the names for the key or column. This is great but look
ugly if your filter is a wildcard or regex, which then becomes your key or
column header. Not wanting to quote the devil but splunk allows the AS
function in the string to accomplish this very easily.
Is there any built in (or plan to build in a ) feature, including JSON
input, where you can rename that filter?
Also, after defining a number of known values in filters this leaves the
visualization wide open for omission of "none of the above", without
writing an extensive filter than includes all of the ones you have defined.
Is there a shortcut for this not documented yet?
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to email@example.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/d8868454-057f-429d-8d9b-a555525bf876%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.