...
Configuration
search on onap* not log*
change "index name or pattern" to onap* and select a "time filter field name" to @timestamp
after create | discoveronap | split rows | aggregatiuon=terms | field=source.keyword | size=100, play
...
...
Configuration
search on onap* not log*
change "index name or pattern" to onap* and select a "time filter field name" to @timestamp
after create | discoveronap | split rows | aggregatiuon=terms | field=source.keyword | size=100, play
...