Hello, I'm using the ELK stack for the first time and I'm trying to visualize some fields.
Let's say that I have a very large number of fields each containing a value. Each of the fields has a different name, but all have the same postfix (e.g. field-1000-postfix=1, field-1001-postfix=3, field-1945-postfix=32, foo-1843-postfix=22). I have been able to make Elasticsearch recognize them as fields with int values using Logstash. As the log files update every few seconds, more fields are added.
Is there a way to find and display 5, for example, of the fields with the largest value with that postfix? I understand that there's a way to find documents with fields using the console in the DevTools menu of Kibana, but I haven't been able to find clear guidance on how to take something like that over to Kibana's Visualize.
I've also seen that using terms can be a way to go. I'm not sure how to add my fields to be associated with a term.
I would be grateful for any insight. Thanks!