I have a pipeline to ingest data into elasticsearch with the following GROK pattern…
"grok": {
"field": "message",
"patterns": ["%{NOTSPACE:ProjectCode},%{DATA:ECVersion},%{DATA:Date},%{INT:TotalPatients:int},%{INT:TotalUsers:int}"]
},
"date": {
"field" : "Date",
"formats" : ["yyyy/MM/dd hh:mm"]
}
I would like to create a bar chart based on the latest value received in the TotalUsers field, grouped on the project code.
Any help would be appreciated.
Garry