# How to search for a complete URL and Create a Visualization for counts

**URL:** https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114
**Category:** Kibana
**Created:** [March 11, 2016, 6:53am UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114 "2016-03-11T06:53:31Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)
#### Post date: [March 11, 2016, 6:53am UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/1 "2016-03-11T06:53:31Z")

</div>

I am not able to search for URL since it has slashes. i.e. [https://123.123.123/MyService/api/calls](https://123.123.123/MyService/api/calls)

Also,  
How can I create a visualization for searched URL counts i.e. how many times a particular URL was invoked ? So the chart should show "X Axis" -\> all the diff. URLs , "Y Axis"-\> Total Count with color separation of each server?

---

<div class="post-metadata">

### Author: ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)
#### Post date: [March 11, 2016, 9:54pm UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/2 "2016-03-11T21:54:23Z")

</div>

Try using this syntax in the filter bar: `<field-name>: "url"`

You can create the visualization you're looking for by using a Filter aggregation. It'll look something like this:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/fb0f7c3b52bbf7062bb5fa7cabe9fe50df5d5915.png)

---

<div class="post-metadata">

### Author: ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)
#### Post date: [March 11, 2016, 11:54pm UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/3 "2016-03-11T23:54:57Z")

</div>

Here is my service log structure. In below scenario I should be getting "[http://servername:8080/MyService/api/orders/phonesearch](http://servername:8080/MyService/api/orders/phonesearch)" URL count as 2. Will the above solution work here ?  
Should I use : "url" or it will be something else for me, such as requestUri : "url".

Also, I need to know how much time my service responded as OK/Failure. i.e. reasonPhrase.

Log 1 -

EventId : 1, Level : Informational, Message : Request, Payload : [sessionID :\*\* 9abab532-5f4e-4050-97e4-416e423cd6f3\*\*] [method : POST] [requestUri : **[http://servername:8080/MyService/api/orders/phonesearch](http://servername:8080/MyService/api/orders/phonesearch)**] [content : {"areaCode":"651","countryCode":"01","number":"2911000"}] , EventName : RequestInfo, Timestamp : 2016-03-11T18:20:42.4351450Z, ProcessId : 7768, ThreadId : 4516

EventId : 2, Level : Informational, Message : Response, Payload : [sessionID : **9abab532-5f4e-4050-97e4-416e423cd6f3**] [reasonPhrase : **ApplicationException**] [content : [{}]

Log 2 -

EventId : 1, Level : Informational, Message : Request, Payload : [sessionID :\*\* 97bab532-5f4e-4050-97e4-416e423cd6f3\*\*] [method : POST] [requestUri : [http://servername:8080/MyService/api/orders/phonesearch](http://servername:8080/MyService/api/orders/phonesearch)] [content : {"areaCode":"651","countryCode":"01","number":"2911000"}] , EventName : RequestInfo, Timestamp : 2016-03-11T18:20:42.4351450Z, ProcessId : 7768, ThreadId : 4516

EventId : 2, Level : Informational, Message : Response, Payload : [sessionID : **97bab532-5f4e-4050-97e4-416e423cd6f3**] [reasonPhrase : **OK**] [content : [{"created":"2011-10-19T16:34:57", "isComplete":"false","isSaleVoided":"false"}]

---

<div class="post-metadata">

### Author: ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)
#### Post date: [March 12, 2016, 12:09am UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/4 "2016-03-12T00:09:16Z")

</div>

You should be able to do:

`requestUri: "http://servername:8080/MyService/api/orders/phonesearch"`

For your second question, on the visualize tab a terms aggregation or a filter aggregation will probably be what you're looking for, depending on whether you want to see which reasonPhrse values are the "top n" or if you want to see counts for specific values.

---

<div class="post-metadata">

### Author: ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)
#### Post date: [March 12, 2016, 1:02am UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/5 "2016-03-12T01:02:18Z")

</div>

How can i combine my reasonphrase: OK and requestURI: url in the filter aggregation ?

Is there a sample link which i can refer to ?

---

<div class="post-metadata">

### Author: ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)
#### Post date: [March 13, 2016, 7:44am UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/6 "2016-03-13T07:44:44Z")

</div>

Just following up on this.

---

<div class="post-metadata">

### Author: ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)
#### Post date: [March 14, 2016, 3:10pm UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/7 "2016-03-14T15:10:22Z")

</div>

You should be able to simply combine the clauses like this:

`requestURI: "uri" AND reasonPhrase: "OK"`

Also, if you need to do anything really complex, you can always click on the "Advanced" dropdown on the filters aggregation editor and use the full JSON query language: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-filters-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-filters-aggregation.html)

---

<div class="post-metadata">

### Author: ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)
#### Post date: [March 15, 2016, 3:54am UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/8 "2016-03-15T03:54:09Z")

</div>

Now, I am trying to read the IIS Logs for pulling the service hits and success/failure count. Since, it has everything in well organized manner and I was suggested to do the same.

2016-03-13 23:59:37 188.14.34.149 GET **/MyService/api/gettimes/350** - 4433 - 111.11.122.192 Java/1.8.0\_45 - **200** 0 0 0

2016-03-13 23:59:37 188.14.34.149 GET **/MyService/api/gettimes/350** - 4433 - 111.11.122.192 Java/1.8.0\_45 - **400** 0 0 0

Can you please help me here to get this into Visualization?

---

<div class="post-metadata">

### Author: ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)
#### Post date: [March 15, 2016, 5:21am UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/9 "2016-03-15T05:21:59Z")

</div>

Is there a way that I can use Regex to pull this info. I have created this

._?(GET|POST|PUT|DELETE)._?(/MyService/api/gettimes/350)._?((1._)|(2._)|(3._)|(4._)|(5._))

---

<div class="post-metadata">

### Author: ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)
#### Post date: [March 15, 2016, 10:18pm UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/10 "2016-03-15T22:18:51Z")

</div>

Any help on this ?

---

<div class="post-metadata">

### Author: ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)
#### Post date: [May 18, 2016, 10:33pm UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/11 "2016-05-18T22:33:38Z")

</div>

Sorry for the incredibly late reply, for some reason I didn't get an email from Discourse when these replies came in and I just noticed them in my unread list.

To answer your question, breaking up a field like that is something you'll need to do at ingestion time. Logstash's [grok](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) would be the natural choice, or in 5.0 you can use the new [ingest node feature](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html) in Elasticsearch.

---

<div class="post-metadata">

### Author: ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)
#### Post date: [May 19, 2016, 5:32am UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/12 "2016-05-19T05:32:01Z")

</div>

Thanks for the reply Bargs.

I got this working already using GROKs. 🙂

---

<div class="post-metadata">

### Author: ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)
#### Post date: [May 19, 2016, 3:38pm UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/13 "2016-05-19T15:38:22Z")

</div>

Awesome, glad you got it working. Sorry again for ridiculously late reply. Now I know not to rely on email notifications 😉

---

<div class="post-metadata">

### Author: ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)
#### Post date: [May 19, 2016, 4:34pm UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/14 "2016-05-19T16:34:38Z")

</div>

Its ok. Glad you replied.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 1:52pm UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114/15 "2017-07-06T13:52:51Z")

</div>


