dutchcoders / marija

Data exploration and visualisation for Elasticsearch and Splunk.
GNU Affero General Public License v3.0
236 stars 29 forks source link

Timed Indexes #85

Closed danielguerra69 closed 6 years ago

danielguerra69 commented 6 years ago

Is there a wildcard way for timed indices like myindex-2018-01-01 ? Can I use myindex-* ?

nl5887 commented 6 years ago

It looks like the fields for wildcard indices could not be retrieved. Something we need to work on.

nl5887 commented 6 years ago

@danielguerra69 we've fixed the issue, you should be able to use wildcard indexes now.

danielguerra69 commented 6 years ago

Thanx I will check it out !

danielguerra69 commented 6 years ago

Works like a charm, now i can make schema's from my ip-lab. Like this research for "unknown" tls user-agents. Great !

screen shot 2018-07-07 at 15 57 58