# How to split values from a column in a table in Kibana?

**URL:** <https://discuss.elastic.co/t/how-to-split-values-from-a-column-in-a-table-in-kibana/196531>\
**Category:** Kibana\
**Created:** [August 23, 2019, 1:09pm UTC](https://discuss.elastic.co/t/how-to-split-values-from-a-column-in-a-table-in-kibana/196531 "2019-08-23T13:09:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![whalien52](https://avatars.discourse-cdn.com/v4/letter/w/b5e925/32.png) [@whalien52](https://discuss.elastic.co/u/whalien52)\
**Post date:** [August 23, 2019, 1:09pm UTC](https://discuss.elastic.co/t/how-to-split-values-from-a-column-in-a-table-in-kibana/196531/1 "2019-08-23T13:09:49Z")

</div>

Hi guys,

I am trying to visualize a Data Table where there is a field called **transactiondata** which is a column in the table and the column contains values like **Key1:Value1**.

What I need to do is I need to display only value Part for each key.  
Suppose there are 10 different values for each key, I only want to see the values for key1 in a table format.  
So, I have tried using filters in bucket aggregation when I am trying to write the query in filter field which is transactiondata: Key1:Value2, it is giving me error.  
Please help me on this. I am looking forward to you guys.

---

<div class="post-metadata">

**Author:** ![jen-huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jen-huang/32/74327_2.png) [@jen-huang](https://discuss.elastic.co/u/jen-huang)\
**Post date:** [August 23, 2019, 7:26pm UTC](https://discuss.elastic.co/t/how-to-split-values-from-a-column-in-a-table-in-kibana/196531/2 "2019-08-23T19:26:41Z")

</div>

Hi, in your visualization buckets, open Advanced and try adding `Key1:.*` to the **Include** field:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bcdb60fe3a00c27d78e306b46071d97b3ff063c0.png)

This should filter this field down to just values that start with `Key1:`. Include and Exclude fields expect regex expressions: [https://www.elastic.co/guide/en/elasticsearch/reference/6.2/search-aggregations-bucket-terms-aggregation.html#\_filtering\_values\_3](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/search-aggregations-bucket-terms-aggregation.html#_filtering_values_3)

---

<div class="post-metadata">

**Author:** ![christophilus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christophilus/32/42991_2.png) [@christophilus](https://discuss.elastic.co/u/christophilus)\
**Post date:** [August 23, 2019, 7:43pm UTC](https://discuss.elastic.co/t/how-to-split-values-from-a-column-in-a-table-in-kibana/196531/3 "2019-08-23T19:43:55Z")

</div>

You could also do this with scripted fields:

```auto
// I created a scripted field "mykey" that looked like this
doc['transactiondata.keyword'].value.splitOnToken(':')[0]

// And I created a scripted field "myvalue" that looked like this
doc['transactiondata.keyword'].value.splitOnToken(':')[0]

```

Then, I created a data table with a filter: `mykey:key1` and just displayed a terms aggregation on `myvalue`.

---

<div class="post-metadata">

**Author:** ![whalien52](https://avatars.discourse-cdn.com/v4/letter/w/b5e925/32.png) [@whalien52](https://discuss.elastic.co/u/whalien52)\
**Post date:** [August 26, 2019, 7:16am UTC](https://discuss.elastic.co/t/how-to-split-values-from-a-column-in-a-table-in-kibana/196531/4 "2019-08-26T07:16:46Z")

</div>

Thanks Jen. I will try this and let you know.  
Thanks for helping.

---

<div class="post-metadata">

**Author:** ![whalien52](https://avatars.discourse-cdn.com/v4/letter/w/b5e925/32.png) [@whalien52](https://discuss.elastic.co/u/whalien52)\
**Post date:** [August 26, 2019, 7:22am UTC](https://discuss.elastic.co/t/how-to-split-values-from-a-column-in-a-table-in-kibana/196531/5 "2019-08-26T07:22:23Z")

</div>

Thanks Chris for helping. I will try this and let you know.  
Btw by Creating a datatable, did you mean Data Table visualization where you added the filter and used terms aggregation?

---

<div class="post-metadata">

**Author:** ![whalien52](https://avatars.discourse-cdn.com/v4/letter/w/b5e925/32.png) [@whalien52](https://discuss.elastic.co/u/whalien52)\
**Post date:** [August 28, 2019, 5:35am UTC](https://discuss.elastic.co/t/how-to-split-values-from-a-column-in-a-table-in-kibana/196531/6 "2019-08-28T05:35:35Z")

</div>

Thanks Chris It worked. I just had to change the array index.

---

<div class="post-metadata">

**Author:** ![whalien52](https://avatars.discourse-cdn.com/v4/letter/w/b5e925/32.png) [@whalien52](https://discuss.elastic.co/u/whalien52)\
**Post date:** [August 28, 2019, 5:37am UTC](https://discuss.elastic.co/t/how-to-split-values-from-a-column-in-a-table-in-kibana/196531/7 "2019-08-28T05:37:25Z")

</div>

Hi, I didnt get the desired output.. it is showing me the entire line and also didnt get the output in a table format.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2019, 5:37am UTC](https://discuss.elastic.co/t/how-to-split-values-from-a-column-in-a-table-in-kibana/196531/8 "2019-09-25T05:37:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
