I wonder if there is a possibility to split field for unique words and count them for top hits?
My example is "message-subject" field.
Data table is fine form me (Visualize)
What I'm looking for (Result):
outgoing - 5
kibana - 4
tld - 4
visualize - 3
timeout - 2
filebeat - 1
... - ...
I would like to analyze logs from MTA, Exchange and maybe mailbox (imap input in logstash) in future...