[DOCS] Updates Discover docs for 8.1 (#125706)
* [DOCS] Updates Discover docs for 8.1 * [DOCS] Updates screenshots * Update docs/user/discover.asciidoc Co-authored-by: Matthias Wilhelm <ankertal@gmail.com> * [DOCS] Addresses review comments * [DOCS] Minor editors Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com> Co-authored-by: Matthias Wilhelm <ankertal@gmail.com>
|
@ -32,16 +32,16 @@ uploaded a file, or added sample data,
|
|||
you get a data view for free, and can start exploring your data.
|
||||
If you loaded your own data, follow these steps to create a data view.
|
||||
|
||||
. Open the main menu, then click to *Stack Management > Data Views*.
|
||||
. Open the main menu, then click *Stack Management > Data Views*.
|
||||
|
||||
. Click *Create data view*.
|
||||
|
||||
[role="screenshot"]
|
||||
image:management/index-patterns/images/create-data-view.png["Create data view"]
|
||||
|
||||
. Start typing in the *name* field, and {kib} looks for the names of
|
||||
indices, data streams, and aliases that match your input.
|
||||
+
|
||||
[role="screenshot"]
|
||||
image:management/index-patterns/images/create-data-view.png["Create data view"]
|
||||
+
|
||||
** To match multiple sources, use a wildcard (*). For example, `filebeat-*` matches
|
||||
`filebeat-apache-a`, `filebeat-apache-b`, and so on.
|
||||
+
|
||||
|
|
|
@ -31,6 +31,18 @@ To resize a column, drag the right edge of the column header until the column is
|
|||
|
||||
Column widths are stored with a saved search. When you visualize saved searches on dashboards, the saved search appears the same as in **Discover**.
|
||||
|
||||
[float]
|
||||
[[document-explorer-row-height]]
|
||||
=== Adjust row height
|
||||
|
||||
To set the row height to 1 or more lines, or automatically
|
||||
adjust the height to fit the contents, click the row height icon
|
||||
image:images/row-height-icon.png[icon to open the Row height pop-up].
|
||||
|
||||
[role="screenshot"]
|
||||
image::images/document-explorer-row-height.png[Row height settings for Document Explroer, width="75%"]
|
||||
|
||||
|
||||
[float]
|
||||
[[document-explorer-sort-data]]
|
||||
=== Sort data
|
||||
|
@ -43,7 +55,7 @@ The default sort is based on the time field, from new to old.
|
|||
[role="screenshot"]
|
||||
image::images/document-explorer-sort-data.png[Pop-up in Document Explorer for sorting columns, width="75%"]
|
||||
|
||||
. To add more fields to the sort, expand the dropdown menu.
|
||||
. To add more fields to the sort, select from the dropdown menu.
|
||||
+
|
||||
By default, columns are sorted in the order they are added.
|
||||
For example, to sort by `order_date` then `geo.country_iso_code`, make sure `order_date` appears first.
|
||||
|
@ -77,14 +89,22 @@ the documents that occurred before and after it.
|
|||
image:images/expand-icon-2.png[double arrow icon to open a flyout with the document details].
|
||||
+
|
||||
[role="screenshot"]
|
||||
image::images/document-explorer-expand.png[Multi field sort in Document Explorer]
|
||||
image::images/document-explorer-expand.png[Expanded view in Document Explorer]
|
||||
|
||||
. Scan through the fields and their values. If you find a field of interest,
|
||||
. Scan through the fields and their values, or search for a field by name.
|
||||
|
||||
. When you find a field of interest,
|
||||
click
|
||||
image:images/actions-icon.png[three dots icon in table column] in the *Actions* column for filters and other controls.
|
||||
. To view documents that occurred before or after the event you are looking at, click <<discover-view-surrounding-documents,**Surrounding documents**>>.
|
||||
image:images/actions-icon.png[three dots icon in table column] in the *Actions* column
|
||||
to:
|
||||
.. Filter the view of the data
|
||||
.. Toggle the field in or out the document table
|
||||
.. Pin the field so it stays at the top
|
||||
|
||||
. For direct access to a particular document, click <<discover-view-single-document,**Single document**>>.
|
||||
|
||||
. To view documents that occurred before or after the event you are looking at, click <<discover-view-surrounding-documents,**Surrounding documents**>>.
|
||||
|
||||
[float]
|
||||
[[document-explorer-full-screen]]
|
||||
=== View documents in fullscreen
|
||||
|
|
|
@ -14,11 +14,9 @@ for the data and its cardinality?
|
|||
This example explores the fields in
|
||||
the <<gs-get-data-into-kibana, sample web logs data>>, or you can use your own data.
|
||||
|
||||
. Open the main menu, click *Stack Managment > Advanced Settings*, search for *Show field statistics*,
|
||||
and turn on the setting.
|
||||
. Open the main menu, and click *Discover*.
|
||||
|
||||
. Open the main menu, click *Discover*, expand the {data-source} dropdown,
|
||||
and select *kibana_sample_data_logs*.
|
||||
. Expand the {data-source} dropdown, and select *kibana_sample_data_logs*.
|
||||
|
||||
. If you don’t see any results, expand the time range, for example, to *Last 7 days*.
|
||||
|
||||
|
|
Before Width: | Height: | Size: 49 KiB After Width: | Height: | Size: 70 KiB |
Before Width: | Height: | Size: 204 KiB After Width: | Height: | Size: 208 KiB |
Before Width: | Height: | Size: 19 KiB |
Before Width: | Height: | Size: 205 KiB After Width: | Height: | Size: 247 KiB |
Before Width: | Height: | Size: 122 KiB After Width: | Height: | Size: 128 KiB |
Before Width: | Height: | Size: 216 KiB After Width: | Height: | Size: 214 KiB |
Before Width: | Height: | Size: 110 KiB After Width: | Height: | Size: 95 KiB |
Before Width: | Height: | Size: 362 KiB After Width: | Height: | Size: 389 KiB |
Before Width: | Height: | Size: 332 KiB After Width: | Height: | Size: 318 KiB |
BIN
docs/discover/images/document-explorer-row-height.png
Normal file
After Width: | Height: | Size: 29 KiB |
Before Width: | Height: | Size: 244 KiB After Width: | Height: | Size: 255 KiB |
Before Width: | Height: | Size: 192 KiB After Width: | Height: | Size: 162 KiB |
Before Width: | Height: | Size: 184 KiB After Width: | Height: | Size: 193 KiB |
Before Width: | Height: | Size: 213 KiB After Width: | Height: | Size: 234 KiB |
BIN
docs/discover/images/row-height-icon.png
Normal file
After Width: | Height: | Size: 3 KiB |
|
@ -7,10 +7,10 @@ Saved searches are good for adding search results to a dashboard,
|
|||
and can also serve as a foundation for building visualizations.
|
||||
|
||||
A saved search stores the query text, filters, and
|
||||
current view of *Discover*—the columns selected in the document table,
|
||||
current view of *Discover*, including the columns selected in the document table,
|
||||
the sort order, and the {data-source}.
|
||||
Saved searches are different from <<save-load-delete-query,saved queries>>, which
|
||||
are primarily used for storing query text and are available in any app with a query bar.
|
||||
are for storing query text and are available in any app with a query bar.
|
||||
|
||||
[role="xpack"]
|
||||
[[discover-read-only-access]]
|
||||
|
|
|
@ -33,16 +33,11 @@ your {data-source} must contain time-based events.
|
|||
. In the expanded view, click **View surrounding documents**.
|
||||
+
|
||||
Documents are displayed using the same set of columns as the *Discover* view from which
|
||||
the context was opened. The anchor document is highlighted in blue.
|
||||
+
|
||||
[role="screenshot"]
|
||||
image::images/discover-context.png[Image showing context view feature, with anchor documents highlighted in blue]
|
||||
+
|
||||
The filters you applied in *Discover* are carried over to the context view. Pinned
|
||||
the context was opened. The filters you applied are also carried over. Pinned
|
||||
filters remain active, while normal filters are copied in a disabled state.
|
||||
+
|
||||
[role="screenshot"]
|
||||
image::images/discover-context-filters-inactive.png[Filter in context view]
|
||||
image::images/discover-context.png[Image showing context view feature, with anchor documents highlighted in blue]
|
||||
|
||||
. To find the documents of interest, add filters.
|
||||
|
||||
|
|
|
@ -8,7 +8,7 @@ What pages on your website contain a
|
|||
specific word or phrase? What events were logged most recently?
|
||||
What processes take longer than 500 milliseconds to respond?
|
||||
|
||||
With *Discover*, you can quickly gain insight to your data: search and filter your data, get information
|
||||
With *Discover*, you can quickly search and filter your data, get information
|
||||
about the structure of the fields, and display your findings in a visualization.
|
||||
You can also customize and save your searches and place them on a dashboard.
|
||||
|
||||
|
@ -19,7 +19,7 @@ image::images/discover.png[A view of the Discover app]
|
|||
[float]
|
||||
=== Explore and query your data
|
||||
|
||||
This tutorial shows you how to use *Discover* to quickly search large amounts of
|
||||
This tutorial shows you how to use *Discover* to search large amounts of
|
||||
data and understand what’s going on at any given time.
|
||||
|
||||
You’ll learn to:
|
||||
|
@ -58,6 +58,10 @@ To view the ecommerce sample data, make sure the {data-source} is set to **kiban
|
|||
+
|
||||
[role="screenshot"]
|
||||
image::images/discover-data-view.png[How to set the {data-source} in Discover, width=50%]
|
||||
+
|
||||
To create a data view for your own data,
|
||||
click the ellipsis icon (…), and then click *Create new data view*.
|
||||
For details, refer to <<data-views, Create a data view.>>
|
||||
|
||||
. Adjust the <<set-time-filter,time range>> to view data for the *Last 7 days*.
|
||||
+
|
||||
|
@ -73,8 +77,8 @@ click and drag the mouse over the chart.
|
|||
=== Explore the fields in your data
|
||||
|
||||
**Discover** includes a table that shows all the documents that match your search.
|
||||
By default, the table includes columns for the time field and the document `_source`,
|
||||
which can be overwhelming. You’ll modify this table to display only your fields of interest.
|
||||
By default, the table includes columns for the time field and the document `_source`.
|
||||
You’ll modify this table to display your fields of interest.
|
||||
|
||||
. Scan through the list of **Available fields** until you find the `manufacturer` field.
|
||||
You can also search for the field by name.
|
||||
|
@ -110,7 +114,7 @@ You can add a runtime field to your {data-source} from inside of **Discover**,
|
|||
and then use that field for analysis and visualizations,
|
||||
the same way you do with other fields.
|
||||
|
||||
. Click the ellipsis icon (...), and then click *Add field to data view*.
|
||||
. Click the ellipsis icon (...), and then click *Add field*.
|
||||
+
|
||||
[role="screenshot"]
|
||||
image:images/add-field-to-data-view.png[Dropdown menu located next to {data-source} field with item for adding a field to a {data-source}, width=50%]
|
||||
|
@ -168,17 +172,19 @@ you can use to build a structured query.
|
|||
Search the ecommerce data for documents where the country matches US:
|
||||
|
||||
. Enter `g`, and then select *geoip.country_iso_code*.
|
||||
. Select *equals some value* and *US*, and then click *Update*.
|
||||
. Select *:* for equals some value and *US*, and then click *Update*.
|
||||
. For a more complex search, try:
|
||||
+
|
||||
`geoip.country_iso_code : US and products.taxless_price >= 75`
|
||||
```ts
|
||||
geoip.country_iso_code : US and products.taxless_price >= 75
|
||||
```
|
||||
|
||||
[float]
|
||||
[[filter-in-discover]]
|
||||
=== Filter your data
|
||||
|
||||
Whereas the query defines the set of documents you are interested in,
|
||||
filters enable you to zero in on different subsets of those documents.
|
||||
filters enable you to zero in on subsets of those documents.
|
||||
You can filter results to include or exclude specific fields, filter for a value in a range,
|
||||
and more.
|
||||
|
||||
|
@ -224,7 +230,7 @@ You can bookmark this document and share the link.
|
|||
|
||||
Save your search so you can repeat it later, generate a CSV report, or use it in visualizations, dashboards, and Canvas workpads.
|
||||
Saving a search saves the query text, filters,
|
||||
and current view of *Discover*—the columns selected in the document table, the sort order, and the {data-source}.
|
||||
and current view of *Discover*, including the columns selected in the document table, the sort order, and the {data-source}.
|
||||
|
||||
. In the toolbar, click **Save**.
|
||||
|
||||
|
@ -287,4 +293,3 @@ include::{kib-repo-dir}/discover/search-sessions.asciidoc[]
|
|||
include::{kib-repo-dir}/discover/document-explorer.asciidoc[]
|
||||
|
||||
include::{kib-repo-dir}/discover/field-statistics.asciidoc[]
|
||||
|
||||
|
|