# help me please 

**URL:** <https://discuss.elastic.co/t/help-me-please/276342>\
**Category:** Kibana\
**Created:** [June 18, 2021, 7:39am UTC](https://discuss.elastic.co/t/help-me-please/276342 "2021-06-18T07:39:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![parai](https://avatars.discourse-cdn.com/v4/letter/p/a183cd/32.png) [@parai](https://discuss.elastic.co/u/parai)\
**Post date:** [June 18, 2021, 7:39am UTC](https://discuss.elastic.co/t/help-me-please/276342/1 "2021-06-18T07:39:49Z")

</div>

Good morning.  
I am using elasticsearch 7.10 and kibana 7.10.  
I'm having some issues with scattering column values in kibana.  
I am new to elk.  
The following contents were worked on kibana dev tool.

Contents of the issue: The data of the bikeId column is normally entered in elasticsearch, but the column value is split based on specific characters when inquiring in the kibana data table. (Appears to split 1 line into 2 lines based on a specific character)

1. The index was created using the script below.

PUT bike\_location2  
{  
"settings": {  
"analysis": {  
"analyzer": {  
"my\_analyzer": {  
"tokenizer": "my\_tokenizer"  
}  
},  
"tokenizer": {  
"my\_tokenizer": {  
"type": "simple\_pattern\_split",  
"pattern": ""  
}  
}  
}  
}  
}

1. We have added a mapping to the index as shown below.

PUT /bike\_location2/\_mapping  
{  
"properties" : {  
"partnerId" : {"type" : "text", "fielddata": true},  
"bikeId" : {"type" : "text", "fielddata": true},  
"gps\_measure\_time" : {"type" : "date", "format" : "yyyy-MM-dd HH:mm:ss"},  
"gps\_measure\_time\_micro\_second" : {"type" : "integer"},  
"gps\_location" : {"type" : "geo\_point"},  
"battery" : {"type" : "float"},  
"speed" : {"type" : "float"},  
"mode" : {"type" : "float"}  
}  
}

1. I put 3 data.

put bike\_location2/\_doc/1  
{  
"partnerId" : "test",  
"bikeId" : "bike::test0001",  
"gps\_measure\_time" : "2021-06-16 16:58:44",  
"gps\_measure\_time\_micro\_second" : "832756",  
"gps\_location" : "37.497236, 127.034078",  
"battery" : "89.5",  
"speed" : "30",  
"mode" : "5"  
}

put bike\_location2/\_doc/2  
{  
"partnerId" : "test",  
"bikeId" : "BIKE-test0001",  
"gps\_measure\_time" : "2021-06-16 16:58:44",  
"gps\_measure\_time\_micro\_second" : "832756",  
"gps\_location" : "37.497236, 127.034078",  
"battery" : "89.5",  
"speed" : "30",  
"mode" : "5"  
}

put bike\_location2/\_doc/3  
{  
"partnerId" : "test",  
"bikeId" : "bike\_test0001",  
"gps\_measure\_time" : "2021-06-16 16:58:44",  
"gps\_measure\_time\_micro\_second" : "832756",  
"gps\_location" : "37.497236, 127.034078",  
"battery" : "89.5",  
"speed" : "30",  
"mode" : "5"  
}

1. When searching with get bike\_location2/\_search , the data is searched well.

{  
"took" : 0,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 1,  
"successful" : 1,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : {  
"value" : 3,  
"relation" : "eq"  
},  
"max\_score" : 1.0,  
"hits" : [  
{  
"\_index" : "bike\_location2",  
"\_type" : "\_doc",  
"\_id" : "1",  
"\_score" : 1.0,  
"\_source" : {  
"partnerId" : "test",  
"bikeId" : "bike::test0001",  
"gps\_measure\_time" : "2021-06-16 16:58:44",  
"gps\_measure\_time\_micro\_second" : "832756",  
"gps\_location" : "37.497236, 127.034078",  
"battery" : "89.5",  
"speed" : "30",  
"mode" : "5"  
}  
},  
{  
"\_index" : "bike\_location2",  
"\_type" : "\_doc",  
"\_id" : "2",  
"\_score" : 1.0,  
"\_source" : {  
"partnerId" : "test",  
"bikeId" : "BIKE-test0001",  
"gps\_measure\_time" : "2021-06-16 16:58:44",  
"gps\_measure\_time\_micro\_second" : "832756",  
"gps\_location" : "37.497236, 127.034078",  
"battery" : "89.5",  
"speed" : "30",  
"mode" : "5"  
}  
},  
{  
"\_index" : "bike\_location2",  
"\_type" : "\_doc",  
"\_id" : "3",  
"\_score" : 1.0,  
"\_source" : {  
"partnerId" : "test",  
"bikeId" : "bike\_test0001",  
"gps\_measure\_time" : "2021-06-16 16:58:44",  
"gps\_measure\_time\_micro\_second" : "832756",  
"gps\_location" : "37.497236, 127.034078",  
"battery" : "89.5",  
"speed" : "30",  
"mode" : "5"  
}  
}  
]  
}  
}

1. Check if the data to be saved is partitioned

- All of them are not divided and are kept as they are.  
(Can I test like this?)

POST bike\_location2/\_analyze  
{  
"analyzer": "my\_analyzer",  
"text": "BIKE-test0001"  
}  
POST bike\_location2/\_analyze  
{  
"analyzer": "my\_analyzer",  
"text": "bike\_test0001"  
}  
POST bike\_location2/\_analyze  
{  
"analyzer": "my\_analyzer",  
"text": "bike::test0001"  
}

1. If you search in kibana's data table, it is split like a capture at the bottom.  
Seniors, please help 😭 I've been searching for days, but I can't find a way

As a reference (although the contents do not match the current configuration), it is the same even if you specify the following options.

PUT /my\_index/\_settings?pretty=true  
{  
"settings" : {  
"analysis": {  
"analyzer": {  
"wordAnalyzer": {  
"type": "custom",  
"tokenizer": "whitespace",  
"filter": [  
"word\_delimiter\_for\_phone","nGram\_filter"  
]  
}  
},  
"filter": {  
"word\_delimiter\_for\_phone": {  
"type": "word\_delimiter",  
"catenate\_all": true,  
"generate\_number\_parts ": false,  
"split\_on\_case\_change": false,  
"generate\_word\_parts": false,  
"split\_on\_numerics": false,  
"preserve\_original": true  
},  
"nGram\_filter": {  
"type": "nGram",  
"min\_gram": 1,  
"max\_gram": 20,  
"token\_chars": [  
"letter"  
]  
}  
}  
}  
}  
}

 ![스크린샷 2021-06-18 오후 1.29.41](https://us1.discourse-cdn.com/elastic/original/3X/1/8/187bcf00d91d7ec27041aa08ac838be3fa3f9c3b.png)

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 18, 2021, 12:54pm UTC](https://discuss.elastic.co/t/help-me-please/276342/2 "2021-06-18T12:54:50Z")

</div>

If you always want to group by the full term, the recommended approach is to use a keyword field instead of a text field (some background here: [Elasticsearch replaces string type with two new types text and keyword. | Elastic Blog](https://www.elastic.co/blog/strings-are-dead-long-live-strings) ). `bikeId` doesn't sound like you would ever want to do full text search on it - I recommend just changing it to a keyword field:

```auto
"bikeId" : {"type" : "keyword"},

```

Then the table should work as you would expect (giving you one row per term in the bike id field)

If you absolutely need full text search on the bike id (which I can't see a good reason for), it's common to configure that as a multi-field in your mapping - see the first example here [fields | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html#multi-fields)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2021, 12:55pm UTC](https://discuss.elastic.co/t/help-me-please/276342/3 "2021-07-16T12:55:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
