Skip to content

[Rollup] Support for filters in rollup job to rollup counts of documents for unstructured text queries into metrics #34921

@mikeh-elastic

Description

@mikeh-elastic

One possible way to rollup unstructured text could be to rollup the document counts for predefined filter aggregations on the data so that dashboards could leverage this rolled up filter count for long term analytics without requiring to store the original raw data.

This would allow better support for rollup log aggregation use cases where parsing of the logs is not complete and the message (or analogous) field is used to drive analytics via filters rather than terms aggregations on structured fields.

Metadata

Metadata

Assignees

No one assigned

    Labels

    :StorageEngine/RollupTurn fine-grained time-based data into coarser-grained data>enhancementTeam:AnalyticsMeta label for analytical engine team (ESQL/Aggs/Geo)

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions