Rollups - Viewing Live and Rollupdata

(Lukas) #1


i really like the rollup feature and i'd like to mix rollup and live data (to fill the gap until data is rolled up) in kibana visualizations. However my rollup data looks different, because every term in my original index I selected as rollup field gets ".terms.value" and ".terms.count" added to its name. So i wonder how can i do a Kibana vis that takes both terms into consideration ? Or am I doing something wrong ?


(Zachary Tong) #2

You'll have to use the RollupSearch endpoint, which is basically a search endpoint that knows how to convert the internal rollup naming convention (.terms.value, etc) into something that's compatible with regular searches.

So in Kibana, you'll need to create a "Rollup Index Pattern", so that Kibana knows to switch over to the rollup search endpoint instead of the regular one. More details here: