Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Custom Background Sets for Significant Term Queries #20047

Closed
red-knight opened this issue Jun 19, 2018 · 3 comments
Closed

Custom Background Sets for Significant Term Queries #20047

red-knight opened this issue Jun 19, 2018 · 3 comments
Labels
enhancement New value added to drive a business result Feature:Visualizations Generic visualization features (in case no more specific feature label is available) Team:Visualizations Visualization editors, elastic-charts and infrastructure

Comments

@red-knight
Copy link

Users should be able to customize the background set for significant term queries when building visualizations in Kibana.

Specific use-case:

Determine unusual user activity by comparing last hour of logs with logs from the same hour period on the same day of the week for the last four weeks.

@legrego legrego added Feature:Visualizations Generic visualization features (in case no more specific feature label is available) triage_needed labels Jun 19, 2018
@timroes timroes added enhancement New value added to drive a business result :New Editor and removed triage_needed labels Jun 20, 2018
@timroes
Copy link
Contributor

timroes commented Jun 20, 2018

You can already today specify the background set, using the "JSON input" under "Advanced Setting" in the significant terms aggregation, by specifying { "background_filter": <any ES query> } (see also Significant Terms aggregation docs.

@red-knight
Copy link
Author

Ah, hah. I must have made a formatting mistaken when I tried it, then.

Thanks, and enjoy your articles.

@timroes timroes added the Team:Visualizations Visualization editors, elastic-charts and infrastructure label Sep 16, 2018
@stratoula
Copy link
Contributor

Thank you for contributing to this issue, however, we are closing this issue due to inactivity as part of a backlog grooming effort. If you believe this feature/bug should still be considered, please reopen with a comment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New value added to drive a business result Feature:Visualizations Generic visualization features (in case no more specific feature label is available) Team:Visualizations Visualization editors, elastic-charts and infrastructure
Projects
None yet
Development

No branches or pull requests

4 participants