Re: Kibana 4 filter editing and event tables gone?

2015-02-13 Thread warpkanal
At least I now got the second part of my question. I simply need to save a 
search in the Discover tab and add that to my dashboard :)
Still I wonder where filter editing has gone...

On Friday, February 13, 2015 at 6:51:13 PM UTC+1, warp...@gmail.com wrote:
>
> Hi,
>
> *1.* I used alot the ability to edit filters in Kibana3. E.g. just 
> clicking on a loupe or dashboard -> automatically creates a filter -> edit 
> the filter to either broaden, narrow or switch the scope.
> Is that gone in Kibana 4? I can seem to only toggle/negate/remove a filter 
> after it got created but cannot seem to change the value anymore.
>
> *2. *Is the plain event/data table gone? I used to have a dashboard where 
> I filter interactively to the data I'm interested in. Then I check my event 
> table (that just lists all data, in my case log events) to read my log 
> events.
> It looks to me like that is now replaced by the Discover tab. When using 
> my dashboards to narrow down my data, I get a nice filter list. However 
> when I now switch to the Discover tab, then this filter list is replaced by 
> what was visible beofre in the Discover tab. => I cannot visually filter 
> anymore with a dashboard to the data I'm interested in and then read the 
> log events for which I filtered down.
>
> But maybe I'm missing something here. Any help appreciated.
>
> Regads,
> Dieter
>

-- 
You received this message because you are subscribed to the Google Groups 
"elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to elasticsearch+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/elasticsearch/6a1c9229-805e-4aed-a4a9-87838969a857%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Kibana 4 filter editing and event tables gone?

2015-02-13 Thread warpkanal
Hi,

*1.* I used alot the ability to edit filters in Kibana3. E.g. just clicking 
on a loupe or dashboard -> automatically creates a filter -> edit the 
filter to either broaden, narrow or switch the scope.
Is that gone in Kibana 4? I can seem to only toggle/negate/remove a filter 
after it got created but cannot seem to change the value anymore.

*2. *Is the plain event/data table gone? I used to have a dashboard where I 
filter interactively to the data I'm interested in. Then I check my event 
table (that just lists all data, in my case log events) to read my log 
events.
It looks to me like that is now replaced by the Discover tab. When using my 
dashboards to narrow down my data, I get a nice filter list. However when I 
now switch to the Discover tab, then this filter list is replaced by what 
was visible beofre in the Discover tab. => I cannot visually filter anymore 
with a dashboard to the data I'm interested in and then read the log events 
for which I filtered down.

But maybe I'm missing something here. Any help appreciated.

Regads,
Dieter

-- 
You received this message because you are subscribed to the Google Groups 
"elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to elasticsearch+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/elasticsearch/313d2a3a-6221-43ad-b266-abe97cf509a4%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: Is it possible to delete data/field without affecting the index?

2015-02-12 Thread warpkanal
Thanks a lot, that sounds exactly like what I was looking for!
Why would you suggest extracting the content myself? Because of the 
"experimental" state of the attachment type plugin?
Even if I'd extract the content myself I wouldn't want to store it in ES 
(as I'd never request it from ES). The only benefit I could think of is the 
ability to reindex inside ES without having my outer system to feed the 
content in again for reindexing.

On Thursday, February 12, 2015 at 11:02:51 PM UTC+1, David Pilato wrote:
>
> You could may be use source exclude: 
> http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/mapping-source-field.html#include-exclude
>
> Though I think it would be better to extract yourself content using Tika 
> if you are using Java and only send what you need to ES.
>
>
> David
>
> Le 12 févr. 2015 à 22:39, warp...@gmail.com  a écrit :
>
> Hi,
>
> I have some terabytes of documents (pdf, office, etc) stored in some 
> system outside of ES. Suppose I want to make them *searchable* with ES, 
> however I will never serve the original documents from ES, but from that 
> other system.
> Is it possible to send the documents to ES (e.g. via base64 encoded field 
> and the attachment type mapping), have ES index them and afterwards delete 
> that base64 field so that the "real content" of my documents is not stored 
> in ES (for cost reasons)?
> Queries will then be served by ES but the real document is served by that 
> other system I have.
>
> Regards,
> Dieter
>
> -- 
> You received this message because you are subscribed to the Google Groups 
> "elasticsearch" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to elasticsearc...@googlegroups.com .
> To view this discussion on the web visit 
> https://groups.google.com/d/msgid/elasticsearch/d084274d-8d50-4fb7-8357-8d53f5177e1f%40googlegroups.com
>  
> 
> .
> For more options, visit https://groups.google.com/d/optout.
>
>

-- 
You received this message because you are subscribed to the Google Groups 
"elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to elasticsearch+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/elasticsearch/b37643b0-c05e-4159-86b4-3f31f8fbfb9d%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Is it possible to delete data/field without affecting the index?

2015-02-12 Thread warpkanal
Hi,

I have some terabytes of documents (pdf, office, etc) stored in some system 
outside of ES. Suppose I want to make them *searchable* with ES, however I 
will never serve the original documents from ES, but from that other system.
Is it possible to send the documents to ES (e.g. via base64 encoded field 
and the attachment type mapping), have ES index them and afterwards delete 
that base64 field so that the "real content" of my documents is not stored 
in ES (for cost reasons)?
Queries will then be served by ES but the real document is served by that 
other system I have.

Regards,
Dieter

-- 
You received this message because you are subscribed to the Google Groups 
"elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to elasticsearch+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/elasticsearch/d084274d-8d50-4fb7-8357-8d53f5177e1f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.