ES|QL grouping functions
The STATS command supports these grouping functions:
BUCKETCreates groups of values (buckets) from a datetime or numeric input.
CATEGORIZEGroups text messages into categories of similarly formatted text values.
TBUCKETCreates timestamp-based buckets aligned to calendar boundaries.
WITHOUT
The INLINE STATS command supports these grouping functions: