# Aggregate based on regular expression in service url

**URL:** https://discuss.elastic.co/t/aggregate-based-on-regular-expression-in-service-url/92530
**Category:** Kibana
**Created:** [July 10, 2017, 8:49pm UTC](https://discuss.elastic.co/t/aggregate-based-on-regular-expression-in-service-url/92530 "2017-07-10T20:49:00Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Arnab\_Karmakar](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@Arnab\_Karmakar](https://discuss.elastic.co/u/Arnab_Karmakar)
#### Post date: [July 10, 2017, 8:49pm UTC](https://discuss.elastic.co/t/aggregate-based-on-regular-expression-in-service-url/92530/1 "2017-07-10T20:49:00Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/3X/c/7/c7973a3436564bb06eea836bc45dc4073f3064bc.png)

Currently API looks like /AddressWEB/address/v5/addresses/some\_dynamic\_id. Now the way I am able to create the visualization, in that unique row is coming for each some\_dynamic\_id.

But I want to get a single row like /AddressWEB/address/v5/addresses/some\_dynamic\_id using regular expression and aggregate the result.

Please let me know if it is possible or not.

---

<div class="post-metadata">

### Author: ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)
#### Post date: [July 11, 2017, 11:48am UTC](https://discuss.elastic.co/t/aggregate-based-on-regular-expression-in-service-url/92530/2 "2017-07-11T11:48:14Z")

</div>

@Arnab_Karmakar I'm having trouble understanding what you're trying to accomplish. Are you trying to view all documents with a specific `api.keyword` field that match a regex?

---

<div class="post-metadata">

### Author: ![Arnab\_Karmakar](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@Arnab\_Karmakar](https://discuss.elastic.co/u/Arnab_Karmakar)
#### Post date: [July 11, 2017, 1:39pm UTC](https://discuss.elastic.co/t/aggregate-based-on-regular-expression-in-service-url/92530/3 "2017-07-11T13:39:25Z")

</div>

Sorry for the confusion!  
api.keyword represents rest-service URL in my application. In the data table of Kibana visualization, I am trying to capture the service call statistics(e.g response time, http status etc). Now in some of the URLs, I have path variable like /AddressWEB/address/v5/addresses/ **_some\_dynamic\_id_** With this when I am splitting table row and aggregating on api.keyword, multiple rows are getting created for the same service call with different path variable. e.g. lets say /AddressWEB/address/v5/addresses service is getting called by dynamic id **_5678-uuio_** and **_8907-iiop_**. So this will create 2 rows in data table like  
/AddressWEB/address/v5/addresses/5678-uuio  
/AddressWEB/address/v5/addresses/8907-iiop

Instead of that I want a single row for service /AddressWEB/address/v5/addresses and aggregate the result irrespective of dynamic id. e.g  
/AddressWEB/address/v5/addresses/{id}

Hope I am able to clear my points here. Else please let me know. Thanks for your quick response!

---

<div class="post-metadata">

### Author: ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)
#### Post date: [July 11, 2017, 8:21pm UTC](https://discuss.elastic.co/t/aggregate-based-on-regular-expression-in-service-url/92530/4 "2017-07-11T20:21:20Z")

</div>

@Arnab_Karmakar unfortunately, you can't do that type of query in Elasticsearch, and I'd recommend extracting out the base-path when you ingest you data into Elasticsearch via Logstash so you can do a simple terms aggregation.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 8, 2017, 8:21pm UTC](https://discuss.elastic.co/t/aggregate-based-on-regular-expression-in-service-url/92530/5 "2017-08-08T20:21:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
