# How can I group a couple of terms behind one name?

**URL:** <https://discuss.elastic.co/t/how-can-i-group-a-couple-of-terms-behind-one-name/27027>\
**Category:** Kibana\
**Created:** [August 7, 2015, 7:09am UTC](https://discuss.elastic.co/t/how-can-i-group-a-couple-of-terms-behind-one-name/27027 "2015-08-07T07:09:22Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![faitlezen](https://avatars.discourse-cdn.com/v4/letter/f/13edae/32.png) [@faitlezen](https://discuss.elastic.co/u/faitlezen)\
**Post date:** [August 7, 2015, 7:09am UTC](https://discuss.elastic.co/t/how-can-i-group-a-couple-of-terms-behind-one-name/27027/1 "2015-08-07T07:09:22Z")

</div>

I'm pretty sure, I once saw a demo of someone extracting all the user agent from some kind of web server log and through adding something in the JSON filed on his visualization widget was able to say "consider everything that's matching `.*Android.*` as `Android`, `.*OSX.*` as `OSX` ... such that at the end without too much effort the person was able to graph OSX vs Windows vs Iphone vs Android ? How do I do the same ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 8, 2015, 12:13am UTC](https://discuss.elastic.co/t/how-can-i-group-a-couple-of-terms-behind-one-name/27027/2 "2015-08-08T00:13:21Z")

</div>

Yeah that'd be Logstash using the useragent filter, then point Kibana to the `useragent.raw` field to read it.

How did you get your data into ES?

---

<div class="post-metadata">

**Author:** ![faitlezen](https://avatars.discourse-cdn.com/v4/letter/f/13edae/32.png) [@faitlezen](https://discuss.elastic.co/u/faitlezen)\
**Post date:** [August 8, 2015, 11:41pm UTC](https://discuss.elastic.co/t/how-can-i-group-a-couple-of-terms-behind-one-name/27027/3 "2015-08-08T23:41:53Z")

</div>

That's not what I have in mind. I was thinking about using a similar strategy for a different use case.  
I have some logs with a service string but some of the services are broken up in sub-services like foo\_master, foo\_worker, foo\_test. I want to sum a certain metrics grouped by service but I wanted to have all the foo services represented by for 1 service name. Ie if I have

```auto
{'service': 'foo_a', 'metric': 1 }, 
{'service': 'foo_b', 'metric': 20 },
{'service': 'foo_c', 'metric': 5 },
{'service': 'bar_a', 'metric': 10 },
{'service': 'bar_b', 'metric': 100 },
{'service': 'baz', 'metric': 50 },

```

I want to do some kind of term aggregation and sum aggregation such that I end up with

```auto
foo: 26
bar: 110
baz: 50

And I would really much prefer doing this at the kibana level so I don't have to store bigger documents in ES
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 9, 2015, 4:30am UTC](https://discuss.elastic.co/t/how-can-i-group-a-couple-of-terms-behind-one-name/27027/4 "2015-08-09T04:30:36Z")

</div>

Ahh ok, basically field aliases, that's coming in a later release 🙂

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [August 11, 2015, 11:32pm UTC](https://discuss.elastic.co/t/how-can-i-group-a-couple-of-terms-behind-one-name/27027/5 "2015-08-11T23:32:51Z")

</div>

This is already in master and will be part of 4.2: [https://github.com/elastic/kibana/issues/2245](https://github.com/elastic/kibana/issues/2245)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 11, 2015, 11:42pm UTC](https://discuss.elastic.co/t/how-can-i-group-a-couple-of-terms-behind-one-name/27027/6 "2015-08-11T23:42:35Z")

</div>

Woohoo!

---

<div class="post-metadata">

**Author:** ![faitlezen](https://avatars.discourse-cdn.com/v4/letter/f/13edae/32.png) [@faitlezen](https://discuss.elastic.co/u/faitlezen)\
**Post date:** [August 13, 2015, 1:15am UTC](https://discuss.elastic.co/t/how-can-i-group-a-couple-of-terms-behind-one-name/27027/7 "2015-08-13T01:15:11Z")

</div>

Sweet

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:14pm UTC](https://discuss.elastic.co/t/how-can-i-group-a-couple-of-terms-behind-one-name/27027/8 "2017-07-06T14:14:53Z")

</div>


