Im testing in Kibana + ES 6.1
Im following guide in this blog https://www.elastic.co/blog/machine-learning-for-nginx-logs - Use Case 2: Changes in Website Behaviour
But i cant see field "nginx.access.response" .. and this field existed data
Im testing in Kibana + ES 6.1
Im following guide in this blog https://www.elastic.co/blog/machine-learning-for-nginx-logs - Use Case 2: Changes in Website Behaviour
But i cant see field "nginx.access.response" .. and this field existed data
Can someone have suggestion?
What does the Index Pattern look like for nginx data? Go to Management -> Index Pattern and select the nginx Index Pattern. Does the field response_code exist. If not, try hitting the "Refresh field list" button in the top left.
Hi,
You can't split a job by a numerical field due to the high cardinality of the field i.e. you could have billions of fields. Only text fields can be used to split data.
Is nginx.access.response also indexed as a keyword field? If so that should appear in the split data drop down list otherwise you will have to re-index the nginx data I'm afraid 
Many thank @dkyle and @richcollier. I got it.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.