# Dynamic Grouping

**URL:** <https://discuss.elastic.co/t/dynamic-grouping/247074>\
**Category:** Kibana\
**Created:** [September 1, 2020, 10:14am UTC](https://discuss.elastic.co/t/dynamic-grouping/247074 "2020-09-01T10:14:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Patrick\_Grasseels](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_grasseels/32/74871_2.png) [@Patrick\_Grasseels](https://discuss.elastic.co/u/Patrick_Grasseels)\
**Post date:** [September 1, 2020, 10:14am UTC](https://discuss.elastic.co/t/dynamic-grouping/247074/1 "2020-09-01T10:14:49Z")

</div>

Hi !

We have a big index, with lot of informations,

Informations sample :

2020-09-01T04:25:18.357Z|LogLevel=Info |MyBusiness.MyLogger|CorrelationId="0000000000000000000"|10.10.10.10|  
POST test/order 1001|InputParameter - Request send to [MYPROJECT] - Unknown Switch Parameter Name [PARAMS1, PARAMS2, PARAMS3, PARAMS4, ...]

What we want to do :

Dynamic aggregation on [PARAMS1, PARAMS2, PARAMS3, PARAMS4, ...]

Sample :

PARAMS1 : 1247 count  
PARAMS2 : 471 count  
PARAMS3 : 871 count  
...

It's possible with Kibana ?

Kind regards,

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [September 2, 2020, 8:43am UTC](https://discuss.elastic.co/t/dynamic-grouping/247074/2 "2020-09-02T08:43:13Z")

</div>

I don't fully understand your question. Is PARAM a field in your index with valyes PARAMS1, PARAMS2, PARAMS3 ?

what do you mean by dynamic aggregation ?

if you have a field X with values x, y, z .... you could do a term aggregation on field X and that will produce a result like you mention: every row is gonna represent one of the possible values (with the one with highest count showing fisst) and second column is gonna be the count.

---

<div class="post-metadata">

**Author:** ![Patrick\_Grasseels](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_grasseels/32/74871_2.png) [@Patrick\_Grasseels](https://discuss.elastic.co/u/Patrick_Grasseels)\
**Post date:** [September 2, 2020, 8:55am UTC](https://discuss.elastic.co/t/dynamic-grouping/247074/3 "2020-09-02T08:55:47Z")

</div>

Hello,

Thank for reponse,  
PARAMS1, PARAMS2, PARAMS3 =\> Is string value in raw\_message.

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [September 2, 2020, 9:32am UTC](https://discuss.elastic.co/t/dynamic-grouping/247074/4 "2020-09-02T09:32:25Z")

</div>

that won't be possible then. you will need to reindex your data and extract those into a separate field.

---

<div class="post-metadata">

**Author:** ![Patrick\_Grasseels](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_grasseels/32/74871_2.png) [@Patrick\_Grasseels](https://discuss.elastic.co/u/Patrick_Grasseels)\
**Post date:** [September 2, 2020, 9:35am UTC](https://discuss.elastic.co/t/dynamic-grouping/247074/5 "2020-09-02T09:35:19Z")

</div>

Hello,

Thank's for response, just after the query we use before in Splunk :

`env:int AND source:my-project AND "Request send to" AND logger:"My.Project.MyLogger" | rex "Unknown Parameter Name /[(?<params>[a-zA-Z,]*)\]"`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2020, 9:35am UTC](https://discuss.elastic.co/t/dynamic-grouping/247074/6 "2020-09-30T09:35:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
