# Display a string value (from a JSON key) in the tabular format of visualisation

**URL:** <https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875>\
**Category:** Kibana\
**Created:** [February 26, 2016, 4:47pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875 "2016-02-26T16:47:15Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ppp](https://avatars.discourse-cdn.com/v4/letter/p/9de0a6/32.png) [@ppp](https://discuss.elastic.co/u/ppp)\
**Post date:** [February 26, 2016, 4:47pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/1 "2016-02-26T16:47:15Z")

</div>

Hello,

I'd really appreciate your help in the following. I am receiving JSON messages in Kibana and in them there is a key called warning. I'd like to create a simple visualisation (in tabular format?) that shows the timestamp of the message and the value of the key warning.

It sounds simple, but for the life of me, I still haven't found a way to do it. Any help?

Many thanks in advance!

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 26, 2016, 7:05pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/2 "2016-02-26T19:05:16Z")

</div>

Is this warning key something kibana sees as a field? If so, on Discover tab you can just mouse over that field and click the Add button that appears. That will cause your time-based data with that field to appear in a table (like response below).

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/154f5da209b1eae5b79a7bca07267233c49a62a3.png)

---

<div class="post-metadata">

**Author:** ![ppp](https://avatars.discourse-cdn.com/v4/letter/p/9de0a6/32.png) [@ppp](https://discuss.elastic.co/u/ppp)\
**Post date:** [February 29, 2016, 6:52am UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/3 "2016-02-29T06:52:11Z")

</div>

Hello Lee,

Many thanks for your reply!

Yes Kibana is seeing the warning key as a field and I have added it (as it shows on your screenshot). It appears fine in the "discover" part of Kibana, however, I am still unable to add it in a visualisation graph to be displayed as part of a data table so that it's easily seen as part of a dashboard.

Any more tips would be highly appreciated!

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 29, 2016, 2:53pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/4 "2016-02-29T14:53:05Z")

</div>

Do you want to see the different values of the warning field over time?

One way, is to create a Data Table visualization like I pasted below.  
The metric aggregation is Count.  
The first Split Rows is a Date Histogram.  
The second Split Rows is Terms response (would be Warning for you).

This puts the different responses and counts within the 3 hour (Auto interval) buckets.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/8b7a8a3ffc9f284194c02d7f99b608b7f43e8c18.png)

Or the same thing graphically on a line chart;

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/2106ee6506b7fd97505a704050e470600b70bd83.png)

---

<div class="post-metadata">

**Author:** ![ppp](https://avatars.discourse-cdn.com/v4/letter/p/9de0a6/32.png) [@ppp](https://discuss.elastic.co/u/ppp)\
**Post date:** [February 29, 2016, 3:00pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/5 "2016-02-29T15:00:03Z")

</div>

Hello Lee,

Thanks for your response once again. How do I use the data table to depict the warning if the warning consists of a sentence (strings), not numeric values, (e.g. "Door X is broken at building Z") ?

If I use your first suggestion I'd get in the responses column the words of the sentence broken down in different lines :-/

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 29, 2016, 3:04pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/6 "2016-02-29T15:04:48Z")

</div>

do you have 'warning.raw'? If so, try that instead of 'warning'.

---

<div class="post-metadata">

**Author:** ![ppp](https://avatars.discourse-cdn.com/v4/letter/p/9de0a6/32.png) [@ppp](https://discuss.elastic.co/u/ppp)\
**Post date:** [February 29, 2016, 3:06pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/7 "2016-02-29T15:06:14Z")

</div>

I am afraid I don't have warning.raw. How do I get that if this is what is going to help me here.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 29, 2016, 6:21pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/8 "2016-02-29T18:21:36Z")

</div>

Note that the Discover tab doesn't show the raw fields, but if you are on the Visualize tab and select the Terms aggregation and then look in the Field selection list it may be there.

Or you might need to change your mapping to store the raw value for your warning.

To see your indices, use this (change host and port if needed);  
[http://localhost:9200/\_aliases?pretty=1](http://localhost:9200/_aliases?pretty=1)

Then to see the mapping of the index you're using use this (change index name from 'logstash-2016.01.20' to your index name);  
[http://localhost:9200/logstash-2016.01.20/\_mapping?pretty=1](http://localhost:9200/logstash-2016.01.20/_mapping?pretty=1)

In my case, on this "agent" field, you can see it will store the raw value.

```
      "agent" : {
        "type" : "string",
        "norms" : {
          "enabled" : false
        },
        "fields" : {
          "raw" : {
            "type" : "string",
            "index" : "not_analyzed"
          }
        }
      },
```

---

<div class="post-metadata">

**Author:** ![ppp](https://avatars.discourse-cdn.com/v4/letter/p/9de0a6/32.png) [@ppp](https://discuss.elastic.co/u/ppp)\
**Post date:** [March 1, 2016, 3:47pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/9 "2016-03-01T15:47:45Z")

</div>

Hm...I've tried so many things and I still cannot sort this out...

I am afraid that on the Visualize tab I cannot find the field in its .raw form, neither I can find a raw key when i check the index mapping...

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [March 1, 2016, 4:26pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/10 "2016-03-01T16:26:21Z")

</div>

The Elasticsearch discuss group would be the best place to get help on changing your mapping to get that raw field.

---

<div class="post-metadata">

**Author:** ![ppp](https://avatars.discourse-cdn.com/v4/letter/p/9de0a6/32.png) [@ppp](https://discuss.elastic.co/u/ppp)\
**Post date:** [March 1, 2016, 5:38pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/11 "2016-03-01T17:38:00Z")

</div>

?Many thanks Lee, I appreciated your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:00pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875/12 "2017-07-06T14:00:42Z")

</div>


