timesketch
timesketch copied to clipboard
Allow terms aggregation to return all buckets
Need to use Composite aggregator for streaming results.
@berggren seeing the number of thumbs up here, can you elaborate on what that means and what effort would be needed?
@berggren can you elaborate what this meant? I have no idea :-)
In order to return all buckets without setting the size
to 10000 (example) then we need to use composit aggregations.
This is not high on the prio list because the use-case is fairly limited.