# How to build visualizations based on String fields

**URL:** <https://discuss.elastic.co/t/how-to-build-visualizations-based-on-string-fields/264000>\
**Category:** Kibana\
**Created:** [February 11, 2021, 10:54am UTC](https://discuss.elastic.co/t/how-to-build-visualizations-based-on-string-fields/264000 "2021-02-11T10:54:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ThePreMan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thepreman/32/82548_2.png) [@ThePreMan](https://discuss.elastic.co/u/ThePreMan)\
**Post date:** [February 11, 2021, 10:54am UTC](https://discuss.elastic.co/t/how-to-build-visualizations-based-on-string-fields/264000/1 "2021-02-11T10:54:54Z")

</div>

Hi there.

I am trying to figure out a way to work with our data in kibana. Problem is, even tough we have a lot of diffrent lines within the Payload part of our logs wich means its kind of difficult to build filters in logstash for every possible line.  
So currently we only have the fields that are always the same.

Payload:

```auto
PathologyProc :: PathologyProc_Pathology_Collector :: 0 :: CPPathologyCollectorCPU ---> [Global CPU] usage: 100

```

E. G. is it possible to read the cpu usage and throw it into a Vega visualization ?

---

<div class="post-metadata">

**Author:** ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)\
**Post date:** [February 11, 2021, 1:38pm UTC](https://discuss.elastic.co/t/how-to-build-visualizations-based-on-string-fields/264000/2 "2021-02-11T13:38:41Z")

</div>

Hi @ThePreMan,

To build meaningful visualizations you'd have to preprocess your data first. There are different ways you can do it, for example:

1. [Logstash grok filter plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)
2. [Grok processor in ingest node](https://www.elastic.co/guide/en/elasticsearch/reference/current/grok-processor.html)
3. or you can trying using [Kibana's Scripted fields](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html)

---

<div class="post-metadata">

**Author:** ![ThePreMan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thepreman/32/82548_2.png) [@ThePreMan](https://discuss.elastic.co/u/ThePreMan)\
**Post date:** [February 16, 2021, 10:42am UTC](https://discuss.elastic.co/t/how-to-build-visualizations-based-on-string-fields/264000/3 "2021-02-16T10:42:52Z")

</div>

Thanks a lot. The scripted fields approach likley is the way to go for us right now. We will probably use the logstash grok filter in long term but it will help us out nontheless

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2021, 10:43am UTC](https://discuss.elastic.co/t/how-to-build-visualizations-based-on-string-fields/264000/4 "2021-03-16T10:43:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
