官术网_书友最值得收藏!

Filter

We can achieve the same search functionality which we have just covered under the search option using the filter option. We do this by providing the fields as source.port, operates as is, and values as 80. We can give this filter a label, such as Port 80 filter, to make it more understandable for an end user, as this label tells us that we are trying to apply a filter for port 80. In the same way, we can create other filters as well, such as for the tcp transport protocol. In this way, we can add filters, apply them, and further drill down by searching on top of that applied filter.

We can also apply the filter directly by clicking on the filter icon in front of any field in a tabular view. This will automatically filter the record by creating a new filter for that field. For example, we have opened the tabular view of a document, and while looking at the fields, we have found a dest.port field, which denotes the destination port. Now, if we want to get data for any particular port number, we can click on the plus search icon in front of this field name to apply the filter on the dest.port field. The filter will pick the value of that particular row against the field name, which can be modified by editing the filter value. The following screenshot shows us the filtered view with the Edit filter box, where we can modify the filter options:

In the preceding screenshot, we are adding the filter for source.port using the Add a filter link. We can also generate the Elasticsearch Query DSL for this by clicking on the Edit Query DSL link in the box. A self-explanatory label can be added for the filter to make it more readable because this label will be shown on the filter and we can easily find out about the filter using its label.

主站蜘蛛池模板: 抚宁县| 克东县| 彰武县| 新源县| 沙坪坝区| 肥东县| 武川县| 吴桥县| 涟水县| 千阳县| 牙克石市| 黑水县| 玛多县| 张北县| 邹平县| 吴堡县| 涞水县| 龙井市| 大埔县| 和平县| 雅安市| 邮箱| 社会| 鲜城| 沙雅县| 手游| 图片| 卢龙县| 手机| 两当县| 精河县| 德昌县| 内乡县| 灯塔市| 邻水| 浏阳市| 新巴尔虎左旗| 泗洪县| 金秀| 虞城县| 高雄县|