# How to take the hostname field in the timelion Kibana

**URL:** <https://discuss.elastic.co/t/how-to-take-the-hostname-field-in-the-timelion-kibana/179168>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [May 1, 2019, 5:07am UTC](https://discuss.elastic.co/t/how-to-take-the-hostname-field-in-the-timelion-kibana/179168 "2019-05-01T05:07:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rocky\_RK](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@Rocky\_RK](https://discuss.elastic.co/u/Rocky_RK)\
**Post date:** [May 1, 2019, 5:07am UTC](https://discuss.elastic.co/t/how-to-take-the-hostname-field-in-the-timelion-kibana/179168/1 "2019-05-01T05:07:06Z")

</div>

I'm trying to to get into the timelion visual where i'm trying to get the two queries..

1. to query the `out of memory` string
2. second one `not responding`

Now, i'm looking if i can get the hostname from the field `syslog_hostname` , so that i can get the hosts where these two string or search are appearing on.  
Like if we can get the top 50 hostnames where these strings appearing ..

Below simple query works fine..

```
 (.es(index=dpc-syslog*, q="out of memory"),.es(index=dpc-syslog*,q="not responding")).range(0, 100).mvavg(30)

```

But when i do below that fails to get anything..

```
(.es(index=dpc-syslog*, q="out of memory"),.es(index=dpc-syslog*,q="syslog_hostname")).range(0, 100).mvavg(30)

```

below is the Jason DOC which you can see the multiple fields..

Below is my actual data doc looks like, where you can see the syslog\_hostname

```
{
  "_index": "dpc-syslog-2019.05.01",
  "_type": "messages",
  "_id": "5mB_cWoB_bwdGMlgphWu",
  "_version": 1,
  "_score": null,
  "_source": {
    "type": "dpc-syslog",
    "received_at": "2019-05-01T03:45:52.200Z",
    "syslog_timestamp": "Apr 30 20:45:51",
    "syslog_severity": "notice",
    "syslog_facility_code": 1,
    "syslog_pid": "4538",
    "syslog_program": "automount",
    "@timestamp": "2019-05-01T03:45:51.000Z",
    "syslog_hostname": "mydbhost01",
    "syslog_severity_code": 5,
    "syslog_facility": "user-level",
    "syslog_message": "key \"euler\" not found in map source(s)."
  },
  "fields": {
    "@timestamp": [
      "2019-05-01T03:45:51.000Z"
    ],
    "received_at": [
      "2019-05-01T03:45:52.200Z"
    ]
  },
  "sort": [
    1556682351000
  ]
}

```

Any help/ direction will be much appreciated..

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [May 1, 2019, 3:40pm UTC](https://discuss.elastic.co/t/how-to-take-the-hostname-field-in-the-timelion-kibana/179168/2 "2019-05-01T15:40:51Z")

</div>

> [@Rocky\_RK](#):
>
> (.es(index=dpc-syslog\*, q="out of memory"),.es(index=dpc-syslog\*,q="syslog\_hostname")).range(0, 100).mvavg(30)

`q="syslog_hostname"` is querying the index for a value of `"syslog_hostname"`. It will not return the value of the `syslog_hostname` field.

You might be able to achieve this by using the `split` parameter. e.g. `.es(index=dpc-syslog*,split=syslog_hostname:5)` where `5` is the number of lines to create.

---

<div class="post-metadata">

**Author:** ![Rocky\_RK](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@Rocky\_RK](https://discuss.elastic.co/u/Rocky_RK)\
**Post date:** [May 1, 2019, 4:13pm UTC](https://discuss.elastic.co/t/how-to-take-the-hostname-field-in-the-timelion-kibana/179168/3 "2019-05-01T16:13:58Z")

</div>

Many thanks for the revert @nickpeihl, i'll try that and will revert you back.

---

<div class="post-metadata">

**Author:** ![Rocky\_RK](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@Rocky\_RK](https://discuss.elastic.co/u/Rocky_RK)\
**Post date:** [May 3, 2019, 10:12am UTC](https://discuss.elastic.co/t/how-to-take-the-hostname-field-in-the-timelion-kibana/179168/4 "2019-05-03T10:12:36Z")

</div>

When i do `.es(index=sj-syslog*, q="Out of memory")` this should show me the searches for the `Out of memory` from the Index `dpc-syslog` but it showing wrong as i have only 28 `Out of memory` count for 12 hours while Timelion show multiple variations.

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/1/718d13ba52211c52968a869e01371d4eaeac530c.png)

and

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/c/2c886114412a8f6c73521e2338c81511b2c9f565.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2019, 10:12am UTC](https://discuss.elastic.co/t/how-to-take-the-hostname-field-in-the-timelion-kibana/179168/5 "2019-05-31T10:12:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
