# Create dynamic labels from a part of es request

**URL:** <https://discuss.elastic.co/t/create-dynamic-labels-from-a-part-of-es-request/212332>\
**Category:** Kibana\
**Created:** [December 18, 2019, 1:26pm UTC](https://discuss.elastic.co/t/create-dynamic-labels-from-a-part-of-es-request/212332 "2019-12-18T13:26:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tofmonaute](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tofmonaute/32/47036_2.png) [@tofmonaute](https://discuss.elastic.co/u/tofmonaute)\
**Post date:** [December 18, 2019, 1:26pm UTC](https://discuss.elastic.co/t/create-dynamic-labels-from-a-part-of-es-request/212332/1 "2019-12-18T13:26:14Z")

</div>

```
 Hi,

```

I try to create a vizualisation with Timelion with dynamic labels ( extracted from request response )

For example: the following search in Discover tools 🙂  
message: "SQL ERROR"

results in following response:  
SQL ERROR occurs in DATABASE ORACLE\_DFS01 at 15:01  
SQL ERROR occurs in DATABASE ORACLE\_DFS02 at 17:05  
SQL ERROR occurs in DATABASE ORACLE\_DFS01 at 19:01  
SQL ERROR occurs in DATABASE ORACLE\_DFS03 at 20:01

I would like to create a vizualization in which i would count all SQL ERRORS for each database:

I would proceed as follow to extract dynamically the label from the result:  
.es(q='message: "SQL ERROR"', index=ref\_rfnd\*).label("$1", " DATABASE\s([a-zA-Z0-9.\_-]+)")

But it did not work

Can you help me ?

Regards

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [December 18, 2019, 7:06pm UTC](https://discuss.elastic.co/t/create-dynamic-labels-from-a-part-of-es-request/212332/2 "2019-12-18T19:06:35Z")

</div>

Hi @tofmonaute,

I found this discuss question that may help by using split method: [Dynamic label in Timelion doesn't work as expected](https://discuss.elastic.co/t/dynamic-label-in-timelion-doesnt-work-as-expected/183249)

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![tofmonaute](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tofmonaute/32/47036_2.png) [@tofmonaute](https://discuss.elastic.co/u/tofmonaute)\
**Post date:** [December 23, 2019, 12:14pm UTC](https://discuss.elastic.co/t/create-dynamic-labels-from-a-part-of-es-request/212332/3 "2019-12-23T12:14:49Z")

</div>

No, it does not help : it just seems ITS NOT POSSIBLE TO MAKE REAL DYNAMIC LABELS with Timelion

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [January 2, 2020, 5:42pm UTC](https://discuss.elastic.co/t/create-dynamic-labels-from-a-part-of-es-request/212332/4 "2020-01-02T17:42:54Z")

</div>

@timroes can you help?

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [January 8, 2020, 11:38am UTC](https://discuss.elastic.co/t/create-dynamic-labels-from-a-part-of-es-request/212332/5 "2020-01-08T11:38:38Z")

</div>

Hi,

if you want to group by the specific database and then count documents per each, you must make sure that the database id/name is stored in a separate field in Elasticsearch. If it is, you can use the `split` parameter in the `.es` function to group by that field. the `label` function simply specifies how the label of the individual series should be formatted, and doesn't group any documents together.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2020, 11:38am UTC](https://discuss.elastic.co/t/create-dynamic-labels-from-a-part-of-es-request/212332/6 "2020-02-05T11:38:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
