Friday, May 20, 2016

Workaround for creating chart from messages with non-numeric fields in Graylog

As we all know, Graylog doesn't support creating a chart on non-numeric value at the moment. There is a neat workaround suggested by Drew Miranda that can fulfil this functionality. I'll try to rephrase it step by step.

  1. Go to Graylog UI page
  2. Make a search for the field and value that you want to represent as a chart
  3. Around the bottom left corner of search page, click all fields
  4. Find timestamp field and generate chart from it
  5. Around top right of the chart, Customize > Value > Total
That's it for a single value chart. But if you want a chart to contain multiple values, keeps going
  1. Redo 2-5 again for different fields
  2. Click and hold on hamburger menu button at the top right of each, drag to merge them
That's neat right?

