ES version 7.6
I am finding difficult to do summarize or transforms on running total values like network traffic metrics.
For example i want to get the max bucket on inbound bytes/s. But prior to that, looks like i have to calculate rate (out of the running total) first.
A simple derivative aggregation may easily hit the too many bucket error. Especially the interval setting in date_histogram is short (e.g 1 minute), or there is additional terms aggregation
While considering transforms, it complains "Unsupported aggregation type [date_histogram]"
Please any suggestion? Thanks in advance.