# Bug in labelling where regex is used?

**URL:** <https://discuss.elastic.co/t/bug-in-labelling-where-regex-is-used/115572>\
**Category:** Kibana\
**Created:** [January 15, 2018, 4:07pm UTC](https://discuss.elastic.co/t/bug-in-labelling-where-regex-is-used/115572 "2018-01-15T16:07:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![emil.mirzayev](https://avatars.discourse-cdn.com/v4/letter/e/ba9def/32.png) [@emil.mirzayev](https://discuss.elastic.co/u/emil.mirzayev)\
**Post date:** [January 15, 2018, 4:07pm UTC](https://discuss.elastic.co/t/bug-in-labelling-where-regex-is-used/115572/1 "2018-01-15T16:07:02Z")

</div>

Hi! I am using timelion with this code `.es(index = measurements, metric = max:value, split = id:4, q = "bar").label(regex = '.*FOO-(.*)', label = '$1 Consumption')`.  
The thing is, I have a column with structure "FOO-BAR (some number)". So, I am using regex in order to match entities in that column and put them as first argument in label. I am expecting something like this in my labels `BAR1 Consumption, BAR2 Consumption` and etc. But instead, I get following:  
`BAR1 > max(value) Consumption, BAR2 > max(value) Consumption`

Is it the way it supposed to work? If I label graphs already why I have also my aggregation there?

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [January 15, 2018, 5:26pm UTC](https://discuss.elastic.co/t/bug-in-labelling-where-regex-is-used/115572/2 "2018-01-15T17:26:29Z")

</div>

Hi Emil,

the regex is actually execute against the legend as is at this point. Meaning you shouldn't make your regex match against the field value, but get rid of the legend function, look how the legend looks, and make your regex match this legend and extract what it needs.

Cheers  
Tim

---

<div class="post-metadata">

**Author:** ![emil.mirzayev](https://avatars.discourse-cdn.com/v4/letter/e/ba9def/32.png) [@emil.mirzayev](https://discuss.elastic.co/u/emil.mirzayev)\
**Post date:** [January 16, 2018, 10:47am UTC](https://discuss.elastic.co/t/bug-in-labelling-where-regex-is-used/115572/3 "2018-01-16T10:47:54Z")

</div>

Hi Tim,

this is my original query without applying the regex part. `.es(index = measurements, metric = max:value, split = meter_id:4, q = "1\-0\:1\.8\.0\*255").derivative()`. This is what I get in my labels:

> q:1-0:1.8.0\*255 \> meter\_id:CUC-DEMO6 \> max(value)

and this is my query with regex. `.es(index = measurements, metric = max:value, split = meter_id:4, q = "1\-0\:1\.8\.0\*255").derivative().label(regex = '.*CUC-(.*)', label = '$1 Consumption')`. This is what I get in response in my label:

> DEMO6 \> max(value) Consumption

My question would be, is this the normal behavior? If yes, how I can "make" ` > max(value)` part disappear?

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [January 16, 2018, 2:44pm UTC](https://discuss.elastic.co/t/bug-in-labelling-where-regex-is-used/115572/4 "2018-01-16T14:44:30Z")

</div>

Try not to match the \> sign in your capture group: `.*CUC-([^>]*).*`, because currently your capture group matches the whole rest of the string (including the aggregation part).

---

<div class="post-metadata">

**Author:** ![emil.mirzayev](https://avatars.discourse-cdn.com/v4/letter/e/ba9def/32.png) [@emil.mirzayev](https://discuss.elastic.co/u/emil.mirzayev)\
**Post date:** [January 16, 2018, 3:24pm UTC](https://discuss.elastic.co/t/bug-in-labelling-where-regex-is-used/115572/5 "2018-01-16T15:24:36Z")

</div>

Thank you Tim,

it did solve my problem. Seems, I haven't quite understood the core idea behind labeling.  
So, it is used to match the label itself, not some columns

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2018, 3:24pm UTC](https://discuss.elastic.co/t/bug-in-labelling-where-regex-is-used/115572/6 "2018-02-13T15:24:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
