To create a new optimizer, start in Kibana so you can test the query you want to use. After that, continue to the Create an optimizer page, where you can configure the optimizer settings.

Before creating an optimizer, you’ll need a timeless account to send the data to. If you need help setting up a timeless account, see Manage timeless accounts.

If you want help updating an existing optimizer, you can skip the first part of this page.

To create an optimizer

Set your query in Kibana

In Kibana, type a query in the query bar and press Enter.

Kibana query bar

Review the results in the histogram and the document table, and make sure your query returned the expected results.

Click Create Optimizer (above the query bar) to open the Create an optimizer page.
Continue with To configure an optimizer.

To configure an optimizer

Configure an Optimizer

Name the optimizer

Type a Name and a detailed Description.

(Optional) Edit the search settings

If you need to, change your optimizer Query and the Accounts that the query will search.

If you use an invalid query, the optimizer will be automatically disabled. Run your query in Kibana so you can be sure you’re getting the expected results.

(Optional) Edit group by settings

To store aggregate results, group your search fields.

Group optimizer fields

Click Group by to add up to 3 groups.

In the Choose fields list, choose a field to group by.

To limit the available fields, choose a log type from the Filter by type list. To show fields for all log types, choose Clear filter.

Set the frequency

In the Trigger section, choose how often this optimizer should run.

Choose a timeless account

In the Action section, choose a timeless account to send to.

Choose an output format

Choose an Output.

To send the raw JSON documents to your timeless account, choose Full log.

To send a summary table, choose Aggregations.

If you added any groups (in step 3), the aggregations table will show the aggregated fields that you used. To change these fields, you’ll need to change your Group by selection.

If you choose Aggregations, click to add a column to the table, and then choose a field to show in the new column.

Optimizer aggregation

Click Save to save your optimizer. will start sending your logs to the configured timeless account.