# Filtering visualization field

**URL:** <https://discuss.elastic.co/t/filtering-visualization-field/61175>\
**Category:** Kibana\
**Created:** [September 21, 2016, 8:01pm UTC](https://discuss.elastic.co/t/filtering-visualization-field/61175 "2016-09-21T20:01:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tiberiu88](https://avatars.discourse-cdn.com/v4/letter/t/e0b2c6/32.png) [@tiberiu88](https://discuss.elastic.co/u/tiberiu88)\
**Post date:** [September 21, 2016, 8:01pm UTC](https://discuss.elastic.co/t/filtering-visualization-field/61175/1 "2016-09-21T20:01:21Z")

</div>

Hello,

I am quite new to Kibana, hoping someone can help me get past an issue I'm having.

I have memory profiling from multiple VMs getting put into elasticsearch using a custom beat.  
When in the Discover, I see all the JSON returns.

eg.  
beat.hostname = Node(1...5) -- I have 5 of these nodes, each with their response  
...  
response.body:{"value":{"used":18213048}} (among other fields)

I'd like to visualize this in a line chart; time on the X-axis, and used memory on the Y-axis, but I'd like to have multiple lines (one for each Node/hostname).

I put time on the X-axis, and, while the Y-axis allows me to select the Average aggregation of response.jsonBody.value.used (which is what I want), it seems to be taking all the values regardless of hostname. Is there a way to filter these so that I can have one line in the graph for each hostname? Something like:

Field1  
response.jsonBody.value.used AND beat.hostname=Node1

Field2  
response.jsonBody.value.used AND beat.hostname=Node2

etc.

Thanks

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [September 21, 2016, 9:47pm UTC](https://discuss.elastic.co/t/filtering-visualization-field/61175/2 "2016-09-21T21:47:07Z")

</div>

hi tiberiu88,

In the visualize panel, in the Data tab, you will see somewhere under the "X-Axis" configuration a button called "split lines". That will allow you to create multiple lines, one for each host.

Choose a "Terms" aggregation, and select the field that contains the hostname.

If you apply these changes, your line chart will split up and show multiple lines, one for each host.

---

<div class="post-metadata">

**Author:** ![tiberiu88](https://avatars.discourse-cdn.com/v4/letter/t/e0b2c6/32.png) [@tiberiu88](https://discuss.elastic.co/u/tiberiu88)\
**Post date:** [September 22, 2016, 8:38pm UTC](https://discuss.elastic.co/t/filtering-visualization-field/61175/3 "2016-09-22T20:38:43Z")

</div>

Thanks for the response. It works, but unfortunately the field that I'm trying to split is "analyzed", and I've tried everything to change it, with no luck.

I opened a new thread as to not spam this one.

> [@Changing beat.hostname to not\_analyzed](https://discuss.elastic.co/t/changing-beat-hostname-to-not-analyzed/61310):
>
> Hi, I've been trying to solve this issue all day, no solutions online work for me. When using topbeat (or another beat), the beat.hostname field (string), comes up as analyzed, screwing up the graphs. I saw that there are two solutions to this: Automatically load a template where you specify "not\_analyzed" for the field. Manually load the same thing using an HTTP PUT. I cannot do #2 due to configurations of my network. I tried #1, with no results. When changing the json.template, I succes…

Any help greatly appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:38pm UTC](https://discuss.elastic.co/t/filtering-visualization-field/61175/4 "2017-07-06T13:38:22Z")

</div>


