Combine two fields of two different log lines in same index pattern

Viewed 82

I'm new to Kibana, i have two log patterns in same index pattern

Example log line 1 : rejected with ID 123456 log line 2 : rebooking is successful for ID 123456 for US country

I need to create bar chart for country base on the matched ID , something like this "select country from log where message contains "rebooking" AND ID is in (select ID from log where message contains "rejected") "

Please help !

1 Answers

The logs that you're inserting into the ES cluster should be normalized further. Index should have fields created on which you want your conditions/actions to be based on. Right now it is as good as searching a text document. There is no way to make sure that the verbiage of the logs will not change causing visualization to be inaccurate.

Related