i've installed the syslog_pri plugin to display syslog facility & severity. i also added a field for translation of severity numbers into strings like critical, warning etc.. this field is called "severity".
this all works as expected and will show up in kibana/discover.
now i want to visualize the count of severity labels (how many criticals, warnings etc. for a given time period).
my problem is...i can't visualize these new data fields because they fail to appear in the list of "terms" or "significant terms".
the reason for that could be the "unknown" data field type status!??! how can i change that?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.