# Count by regex pattern

**URL:** <https://discuss.elastic.co/t/count-by-regex-pattern/83395>\
**Category:** Kibana\
**Created:** [April 24, 2017, 10:03am UTC](https://discuss.elastic.co/t/count-by-regex-pattern/83395 "2017-04-24T10:03:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexkl](https://avatars.discourse-cdn.com/v4/letter/a/858c86/32.png) [@Alexkl](https://discuss.elastic.co/u/Alexkl)\
**Post date:** [April 24, 2017, 10:03am UTC](https://discuss.elastic.co/t/count-by-regex-pattern/83395/1 "2017-04-24T10:03:04Z")

</div>

I am struggling with a pie chart visualisation in kibana (5.2.2) I have a field url wich contains things like :

[https://fhfhf.jffjr.com/ping?toto=tata](https://fhfhf.jffjr.com/ping?toto=tata)  
[https://fhfhf.jffjr.com/user=tu](https://fhfhf.jffjr.com/user=tu)  
[https://fhfhf.jffjr.com/ping?tutu=tata](https://fhfhf.jffjr.com/ping?tutu=tata)  
I want to get in a pie chart the count of url fields containing the pattern ._ping._ vs others.

I didn't find a way to do it. It's sliced by the full keyword. Is there a way to do it without scripting ?

Thanks !

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [April 24, 2017, 11:00pm UTC](https://discuss.elastic.co/t/count-by-regex-pattern/83395/2 "2017-04-24T23:00:55Z")

</div>

If you are trying to avoid scripting then I imagine you are worried about the performance of this query. If so, then regular expressions probably aren't going to be the best, but you can do this with a regex in the "filters" aggregation.

See [https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#\_regular\_expressions](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#_regular_expressions)

If regexp is still too slow, I suggest pre-processing the logs with something like logstash to extract the bit of data you are trying to understand (maybe the path of the url?)

---

<div class="post-metadata">

**Author:** ![Alexkl](https://avatars.discourse-cdn.com/v4/letter/a/858c86/32.png) [@Alexkl](https://discuss.elastic.co/u/Alexkl)\
**Post date:** [April 26, 2017, 8:16am UTC](https://discuss.elastic.co/t/count-by-regex-pattern/83395/3 "2017-04-26T08:16:34Z")

</div>

Hello,

You are right i was afraid of the performance of the query with a script and i wished to avoid adding a logstash filter.  
I will try with the filter and if it didn't work i will make some tests with scripting.

Thanks !  
Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2017, 8:20am UTC](https://discuss.elastic.co/t/count-by-regex-pattern/83395/4 "2017-05-24T08:20:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
