I am trying to create visualization that show per specific log the count of ERROR, WARN & INFO messages.
I have tried to create the json input for getting all to message filed that contains [ERROR] but it did not show any.
How can I make it?
You can add the error type bucket to your aggregtation
or use the filter aggregation as a bucket in your viz
That should work if the field message is mapped as text
It gives me results while Discovering:
Does not it means it text?
Yes if it gives results on discovery it should give same in viz
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.