# Issue with timelion regex label

**URL:** <https://discuss.elastic.co/t/issue-with-timelion-regex-label/209973>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [November 29, 2019, 1:50pm UTC](https://discuss.elastic.co/t/issue-with-timelion-regex-label/209973 "2019-11-29T13:50:39Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![mikecote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikecote/32/58549_2.png) [@mikecote](https://discuss.elastic.co/u/mikecote)\
**Post date:** [November 29, 2019, 8:05pm UTC](https://discuss.elastic.co/t/issue-with-timelion-regex-label/209973/2 "2019-11-29T20:05:08Z")

</div>

Hi @kristoflarcher,

I believe this is because the regex applies to the generated label from .es(...) and doesn't apply to the data returned. In your scenario, the regex extracts from `q:msg: "Detected server" AND msg: "started" > count`.

A more detailed explanation can be found here: [Timelion: how generate .label() dynamically?](https://discuss.elastic.co/t/timelion-how-generate-label-dynamically/85072/2).

---

_[View the full topic](https://discuss.elastic.co/t/issue-with-timelion-regex-label/209973)._
