I am trying to visualize a timelion and this is the query i am using: .es(index=investigation_master_index,timefield=uco-observable:sentTime.@value,split=uco-observable:messageText.keyword:1000)
the messageText has data inside as well as the sentTime and i just want to visualize their correllation. What does VALUE_NULL mean, does it mean that the uco-observable:messageText.keyword doesnt exist? or that it is empty? I have looked everywhere for this and found nothing unfortunately. Maybe the solution is something simple, that I cannot think right now.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.