# Counting string occurrences in string

**URL:** <https://discuss.elastic.co/t/counting-string-occurrences-in-string/135597>\
**Category:** Kibana\
**Created:** [June 12, 2018, 8:46pm UTC](https://discuss.elastic.co/t/counting-string-occurrences-in-string/135597 "2018-06-12T20:46:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![gregpaskal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregpaskal/32/26101_2.png) [@gregpaskal](https://discuss.elastic.co/u/gregpaskal)\
**Post date:** [June 12, 2018, 8:46pm UTC](https://discuss.elastic.co/t/counting-string-occurrences-in-string/135597/1 "2018-06-12T20:46:21Z")

</div>

I'm looking for a way to count the number of string occurrences within a string.

Say for instance I have the following string "Hello World" and I wanted to return the number of "l" found within this string. How would I script this in "Painless"

Thanks,  
Greg

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 13, 2018, 1:23pm UTC](https://discuss.elastic.co/t/counting-string-occurrences-in-string/135597/2 "2018-06-13T13:23:16Z")

</div>

@gregpaskal where are you wanting to use this information, are you intending to build a Visualization using this information, and is this a set "string" that you're looking to count the occurrences of?

---

<div class="post-metadata">

**Author:** ![gregpaskal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregpaskal/32/26101_2.png) [@gregpaskal](https://discuss.elastic.co/u/gregpaskal)\
**Post date:** [June 13, 2018, 3:00pm UTC](https://discuss.elastic.co/t/counting-string-occurrences-in-string/135597/3 "2018-06-13T15:00:05Z")

</div>

@Brandon_Kobel, happy to have your response. You are correct, I will be trying to build another visualization, similar to the last one you assisted me with. Yes, I will be searching for a string (keywords) within a field called payload.test\_case\_exceptions.

**What I'm trying to accomplish** :  
Raise awareness through a counter/metric/visualization when certain keywords show up in the **payload.test\_case\_exceptions** field.

**Details** :

1. I have a field called "payload.test\_case\_exceptions".
2. Anytime a test case fails, verbose details pertaining to the failure are recorded in the payload.test\_case\_exceptions field.

**Example data recorded in payload.test\_case\_exceptions field upon failure.**

> [FAIL] 1 of 3 - Not Exist ID:003 - [**server**] found within [Your browser sent a request that this server could not understand.]  
> [FAIL] 2 of 3 - Not Exist ID:003 - [**server**] found within [Size of a request header field exceeds server limit]  
> [FAIL] 3 of 3 - Not Exist ID:004 - [**Bad Request**] found within [400 Bad Request]

Anytime " **server**" is recorded in the payload.test\_case\_exceptions field, I want to call attention to that on dashboard, through a new visualization dedicated to errors that require higher priority attention. I have a number of keywords or phrases (like " **server**" " **Bad Request**") I'd like to search for in the payload.test\_case\_exceptions field.

**What I've tried to date** :  
I initially tried to create a scripted field that would perform this type of functionality and record a count of how many times a keyword (server, Bad Request, etc). was found in the payload.test\_case\_exceptions field but it was simply too much overhead for our elastic configuration and I got all sorts of shard errors.

**Where I think I should explore next** :  
I think I'd like to approach this challenge with Visual Builder again, this time, trying to figure out how it can be used to identify these keywords (server, Bad Request, etc) within payload.test\_case\_exceptions. This would make it easier to add new keywords of phrases that I want to raise awareness to in the future.

Any help or direction @Brandon_Kobel would be greatly appreciated.

Greg

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 13, 2018, 3:22pm UTC](https://discuss.elastic.co/t/counting-string-occurrences-in-string/135597/4 "2018-06-13T15:22:28Z")

</div>

Thanks for the detailed description @gregpaskal. You could potentially use a scripted field to do this, but you have a couple other options as well.

Is the `payload.test_case_exceptions` field `text` or a `keyword`, or both? If you're storing the `payload.test_case_exceptions` as a keyword, then you can use a a filter aggregation similar to the following to bucket all of these exceptions similar to the following:

 ![51%20AM](https://us1.discourse-cdn.com/elastic/original/3X/4/5/45346e680366c69e03059400f6acd601cc1f2097.png)

If we're dealing with a really large amount of data, this isn't going to be the fastest approach, and I'd suggest using Logstash and the [grok filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) to extract this logic into a boolean field, which will make this a lot more scalable.

---

<div class="post-metadata">

**Author:** ![gregpaskal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregpaskal/32/26101_2.png) [@gregpaskal](https://discuss.elastic.co/u/gregpaskal)\
**Post date:** [June 14, 2018, 11:56am UTC](https://discuss.elastic.co/t/counting-string-occurrences-in-string/135597/5 "2018-06-14T11:56:50Z")

</div>

@Brandon_Kobel, I had success yesterday actually following much of what I learned in the previous visualization aggregation. The conciseness of the visualization is awesome, packing in a lot of critical information into a small space. From the dashboard that contains these metrics, I can fairly quickly derive where we have higher risk and where we have an acceptable level over a weeks worth of automated testing results.

Thanks again for the coaching. I have my next project in mind based upon yesterdays results.

Greg

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 14, 2018, 12:21pm UTC](https://discuss.elastic.co/t/counting-string-occurrences-in-string/135597/6 "2018-06-14T12:21:29Z")

</div>

@gregpaskal that's awesome, your detailed and clear descriptions of the problems you're trying to solve make our interactions productive and enjoyable!

---

<div class="post-metadata">

**Author:** ![gregpaskal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregpaskal/32/26101_2.png) [@gregpaskal](https://discuss.elastic.co/u/gregpaskal)\
**Post date:** [June 14, 2018, 7:32pm UTC](https://discuss.elastic.co/t/counting-string-occurrences-in-string/135597/7 "2018-06-14T19:32:30Z")

</div>

Thanks for your help @Brandon_Kobel.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2018, 7:32pm UTC](https://discuss.elastic.co/t/counting-string-occurrences-in-string/135597/8 "2018-07-12T19:32:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
