[DOCS] Updates Discover docs for 8.1 (#125706)

* [DOCS] Updates Discover docs for 8.1

* [DOCS] Updates screenshots

* Update docs/user/discover.asciidoc

Co-authored-by: Matthias Wilhelm <ankertal@gmail.com>

* [DOCS] Addresses review comments

* [DOCS] Minor editors

Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
Co-authored-by: Matthias Wilhelm <ankertal@gmail.com>
This commit is contained in:
gchaps 2022-02-17 07:18:52 -08:00 committed by GitHub
parent ea6be3c8d5
commit 888d144802
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
21 changed files with 50 additions and 32 deletions

View file

@ -32,16 +32,16 @@ uploaded a file, or added sample data,
you get a data view for free, and can start exploring your data.
If you loaded your own data, follow these steps to create a data view.
. Open the main menu, then click to *Stack Management > Data Views*.
. Open the main menu, then click *Stack Management > Data Views*.
. Click *Create data view*.
[role="screenshot"]
image:management/index-patterns/images/create-data-view.png["Create data view"]
. Start typing in the *name* field, and {kib} looks for the names of
indices, data streams, and aliases that match your input.
+
[role="screenshot"]
image:management/index-patterns/images/create-data-view.png["Create data view"]
+
** To match multiple sources, use a wildcard (*). For example, `filebeat-*` matches
`filebeat-apache-a`, `filebeat-apache-b`, and so on.
+

View file

@ -31,6 +31,18 @@ To resize a column, drag the right edge of the column header until the column is
Column widths are stored with a saved search. When you visualize saved searches on dashboards, the saved search appears the same as in **Discover**.
[float]
[[document-explorer-row-height]]
=== Adjust row height
To set the row height to 1 or more lines, or automatically
adjust the height to fit the contents, click the row height icon
image:images/row-height-icon.png[icon to open the Row height pop-up].
[role="screenshot"]
image::images/document-explorer-row-height.png[Row height settings for Document Explroer, width="75%"]
[float]
[[document-explorer-sort-data]]
=== Sort data
@ -43,7 +55,7 @@ The default sort is based on the time field, from new to old.
[role="screenshot"]
image::images/document-explorer-sort-data.png[Pop-up in Document Explorer for sorting columns, width="75%"]
. To add more fields to the sort, expand the dropdown menu.
. To add more fields to the sort, select from the dropdown menu.
+
By default, columns are sorted in the order they are added.
For example, to sort by `order_date` then `geo.country_iso_code`, make sure `order_date` appears first.
@ -77,14 +89,22 @@ the documents that occurred before and after it.
image:images/expand-icon-2.png[double arrow icon to open a flyout with the document details].
+
[role="screenshot"]
image::images/document-explorer-expand.png[Multi field sort in Document Explorer]
image::images/document-explorer-expand.png[Expanded view in Document Explorer]
. Scan through the fields and their values. If you find a field of interest,
. Scan through the fields and their values, or search for a field by name.
. When you find a field of interest,
click
image:images/actions-icon.png[three dots icon in table column] in the *Actions* column for filters and other controls.
. To view documents that occurred before or after the event you are looking at, click <<discover-view-surrounding-documents,**Surrounding documents**>>.
image:images/actions-icon.png[three dots icon in table column] in the *Actions* column
to:
.. Filter the view of the data
.. Toggle the field in or out the document table
.. Pin the field so it stays at the top
. For direct access to a particular document, click <<discover-view-single-document,**Single document**>>.
. To view documents that occurred before or after the event you are looking at, click <<discover-view-surrounding-documents,**Surrounding documents**>>.
[float]
[[document-explorer-full-screen]]
=== View documents in fullscreen

View file

@ -14,11 +14,9 @@ for the data and its cardinality?
This example explores the fields in
the <<gs-get-data-into-kibana, sample web logs data>>, or you can use your own data.
. Open the main menu, click *Stack Managment > Advanced Settings*, search for *Show field statistics*,
and turn on the setting.
. Open the main menu, and click *Discover*.
. Open the main menu, click *Discover*, expand the {data-source} dropdown,
and select *kibana_sample_data_logs*.
. Expand the {data-source} dropdown, and select *kibana_sample_data_logs*.
. If you dont see any results, expand the time range, for example, to *Last 7 days*.

Binary file not shown.

Before

Width:  |  Height:  |  Size: 49 KiB

After

Width:  |  Height:  |  Size: 70 KiB

Before After
Before After

Binary file not shown.

Before

Width:  |  Height:  |  Size: 204 KiB

After

Width:  |  Height:  |  Size: 208 KiB

Before After
Before After

Binary file not shown.

Before

Width:  |  Height:  |  Size: 19 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 205 KiB

After

Width:  |  Height:  |  Size: 247 KiB

Before After
Before After

Binary file not shown.

Before

Width:  |  Height:  |  Size: 122 KiB

After

Width:  |  Height:  |  Size: 128 KiB

Before After
Before After

Binary file not shown.

Before

Width:  |  Height:  |  Size: 216 KiB

After

Width:  |  Height:  |  Size: 214 KiB

Before After
Before After

Binary file not shown.

Before

Width:  |  Height:  |  Size: 110 KiB

After

Width:  |  Height:  |  Size: 95 KiB

Before After
Before After

Binary file not shown.

Before

Width:  |  Height:  |  Size: 362 KiB

After

Width:  |  Height:  |  Size: 389 KiB

Before After
Before After

Binary file not shown.

Before

Width:  |  Height:  |  Size: 332 KiB

After

Width:  |  Height:  |  Size: 318 KiB

Before After
Before After

Binary file not shown.

After

Width:  |  Height:  |  Size: 29 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 244 KiB

After

Width:  |  Height:  |  Size: 255 KiB

Before After
Before After

Binary file not shown.

Before

Width:  |  Height:  |  Size: 192 KiB

After

Width:  |  Height:  |  Size: 162 KiB

Before After
Before After

Binary file not shown.

Before

Width:  |  Height:  |  Size: 184 KiB

After

Width:  |  Height:  |  Size: 193 KiB

Before After
Before After

Binary file not shown.

Before

Width:  |  Height:  |  Size: 213 KiB

After

Width:  |  Height:  |  Size: 234 KiB

Before After
Before After

Binary file not shown.

After

Width:  |  Height:  |  Size: 3 KiB

View file

@ -7,10 +7,10 @@ Saved searches are good for adding search results to a dashboard,
and can also serve as a foundation for building visualizations.
A saved search stores the query text, filters, and
current view of *Discover*&mdash;the columns selected in the document table,
current view of *Discover*, including the columns selected in the document table,
the sort order, and the {data-source}.
Saved searches are different from <<save-load-delete-query,saved queries>>, which
are primarily used for storing query text and are available in any app with a query bar.
are for storing query text and are available in any app with a query bar.
[role="xpack"]
[[discover-read-only-access]]

View file

@ -33,16 +33,11 @@ your {data-source} must contain time-based events.
. In the expanded view, click **View surrounding documents**.
+
Documents are displayed using the same set of columns as the *Discover* view from which
the context was opened. The anchor document is highlighted in blue.
+
[role="screenshot"]
image::images/discover-context.png[Image showing context view feature, with anchor documents highlighted in blue]
+
The filters you applied in *Discover* are carried over to the context view. Pinned
the context was opened. The filters you applied are also carried over. Pinned
filters remain active, while normal filters are copied in a disabled state.
+
[role="screenshot"]
image::images/discover-context-filters-inactive.png[Filter in context view]
image::images/discover-context.png[Image showing context view feature, with anchor documents highlighted in blue]
. To find the documents of interest, add filters.

View file

@ -8,7 +8,7 @@ What pages on your website contain a
specific word or phrase? What events were logged most recently?
What processes take longer than 500 milliseconds to respond?
With *Discover*, you can quickly gain insight to your data: search and filter your data, get information
With *Discover*, you can quickly search and filter your data, get information
about the structure of the fields, and display your findings in a visualization.
You can also customize and save your searches and place them on a dashboard.
@ -19,7 +19,7 @@ image::images/discover.png[A view of the Discover app]
[float]
=== Explore and query your data
This tutorial shows you how to use *Discover* to quickly search large amounts of
This tutorial shows you how to use *Discover* to search large amounts of
data and understand whats going on at any given time.
Youll learn to:
@ -58,6 +58,10 @@ To view the ecommerce sample data, make sure the {data-source} is set to **kiban
+
[role="screenshot"]
image::images/discover-data-view.png[How to set the {data-source} in Discover, width=50%]
+
To create a data view for your own data,
click the ellipsis icon (…​), and then click *Create new data view*.
For details, refer to <<data-views, Create a data view.>>
. Adjust the <<set-time-filter,time range>> to view data for the *Last 7 days*.
+
@ -73,8 +77,8 @@ click and drag the mouse over the chart.
=== Explore the fields in your data
**Discover** includes a table that shows all the documents that match your search.
By default, the table includes columns for the time field and the document `_source`,
which can be overwhelming. Youll modify this table to display only your fields of interest.
By default, the table includes columns for the time field and the document `_source`.
Youll modify this table to display your fields of interest.
. Scan through the list of **Available fields** until you find the `manufacturer` field.
You can also search for the field by name.
@ -110,7 +114,7 @@ You can add a runtime field to your {data-source} from inside of **Discover**,
and then use that field for analysis and visualizations,
the same way you do with other fields.
. Click the ellipsis icon (...), and then click *Add field to data view*.
. Click the ellipsis icon (...), and then click *Add field*.
+
[role="screenshot"]
image:images/add-field-to-data-view.png[Dropdown menu located next to {data-source} field with item for adding a field to a {data-source}, width=50%]
@ -168,17 +172,19 @@ you can use to build a structured query.
Search the ecommerce data for documents where the country matches US:
. Enter `g`, and then select *geoip.country_iso_code*.
. Select *equals some value* and *US*, and then click *Update*.
. Select *:* for equals some value and *US*, and then click *Update*.
. For a more complex search, try:
+
`geoip.country_iso_code : US and products.taxless_price >= 75`
```ts
geoip.country_iso_code : US and products.taxless_price >= 75
```
[float]
[[filter-in-discover]]
=== Filter your data
Whereas the query defines the set of documents you are interested in,
filters enable you to zero in on different subsets of those documents.
filters enable you to zero in on subsets of those documents.
You can filter results to include or exclude specific fields, filter for a value in a range,
and more.
@ -224,7 +230,7 @@ You can bookmark this document and share the link.
Save your search so you can repeat it later, generate a CSV report, or use it in visualizations, dashboards, and Canvas workpads.
Saving a search saves the query text, filters,
and current view of *Discover*&mdash;the columns selected in the document table, the sort order, and the {data-source}.
and current view of *Discover*, including the columns selected in the document table, the sort order, and the {data-source}.
. In the toolbar, click **Save**.
@ -287,4 +293,3 @@ include::{kib-repo-dir}/discover/search-sessions.asciidoc[]
include::{kib-repo-dir}/discover/document-explorer.asciidoc[]
include::{kib-repo-dir}/discover/field-statistics.asciidoc[]