To create a new optimizer, you’ll start in Kibana so you can test the query you want to use. After that, you’ll continue to the Create a New Optimizer page, where you can configure the optimizer settings.

Before creating an optimizer, you’ll need a timeless account to send the data to. If you need help setting up a timeless account, see Manage timeless accounts.

If you want help updating an existing optimizer, you can skip the first part of this page.

To start a new optimizer

Kibana query bar

Set your query in Kibana

In Kibana, type a query in the query bar and press Enter. Review the results in the histogram and the document table, and make sure your query returned the expected results.

Click Create Alert > Create Optimizer (to the right of the query bar). The Create a New Optimizer page is shown. Continue with To configure an optimizer.

To configure an optimizer

Configure an Optimizer

Name the optimizer

Type a Name and a detailed Description.

(Optional) Edit the search settings

If you need to, change your optimizer Query and the Accounts that the query will search.

If you use an invalid query, the optimizer will be automatically disabled. Run your query in Kibana so you can be sure you’re getting the expected results.

(Optional) Edit group by settings

To store aggregate results, group your search fields.

Group alert fields

Click Add group by to add up to 3 groups.

In the Select Field list, choose a field to group by.

To limit the available fields, choose a log type from the Filter by type list. To show fields for all log types, choose Clear filter.

Set the frequency

In the Trigger section, choose how often this optimizer should run.

Choose a timeless account

In the Action section, choose a timeless account to send to.

Choose an output format

Choose an Output.

To send the raw JSON documents to your timeless account, choose Default format. To send a summary table, choose Custom format.

If you added any groups (in step 3), the custom format table will show the aggregated fields that you used. To change these fields, you’ll need to change your Group by selection.

If you choose Custom format, click to add a column to the table, and then choose a field to show in the new column.

Click Save to save your optimizer. will start sending your logs to the configured timeless account.