Some types of log documents don't have a message but consist purely of structured fields. In order to give the user an overview of those we could replace the categorization aggregation with a terms or significant terms analysis and do a change point detection for the buckets produced by those. The results could then be shown in the same data grid as the categories.
:notebook: Summary
Some types of log documents don't have a message but consist purely of structured fields. In order to give the user an overview of those we could replace the categorization aggregation with a terms or significant terms analysis and do a change point detection for the buckets produced by those. The results could then be shown in the same data grid as the categories.
:heavy_check_mark: Acceptance criteria
This task includes significant amounts of research and experimentation. Therefore the acceptance criteria will change over time.
message
field are shown in the data grid.