# Kibana data table Split row on String with pipe seperator

**URL:** <https://discuss.elastic.co/t/kibana-data-table-split-row-on-string-with-pipe-seperator/196964>\
**Category:** Kibana\
**Created:** [August 27, 2019, 3:03pm UTC](https://discuss.elastic.co/t/kibana-data-table-split-row-on-string-with-pipe-seperator/196964 "2019-08-27T15:03:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kailayla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kailayla/32/53090_2.png) [@Kailayla](https://discuss.elastic.co/u/Kailayla)\
**Post date:** [August 27, 2019, 3:03pm UTC](https://discuss.elastic.co/t/kibana-data-table-split-row-on-string-with-pipe-seperator/196964/1 "2019-08-27T15:03:20Z")

</div>

Hello,

I just started working with Kibana and I am just learning the ropes.  
I have log messages in a data table, and I want to see the ones that occur the most.  
There are key values in the messages that differ sometimes so they mess up the results when using the complete error message.  
They are structured a bit like this.  
"Couldn't find the last element | id=123 | version=2.0"

What I would like to do is have the aggregation on the Terms, but not on the full message but only on the first part. So from start to |

Could any of you help me with this?

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [August 28, 2019, 2:35pm UTC](https://discuss.elastic.co/t/kibana-data-table-split-row-on-string-with-pipe-seperator/196964/2 "2019-08-28T14:35:26Z")

</div>

Kibana is not meant for doing this kind of data processing, although there are options. In general, if you are trying to create structured data from logs I would recommend using an [ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html). For example, you could set up a pipeline that splits on the pipe character [using the split processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/split-processor.html).

Your other options are:

- Use a [scripted aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/search-aggregations-pipeline-bucket-script-aggregation.html) where you write a script to split the strings
- Use a [Vega visualization](https://www.elastic.co/guide/en/kibana/7.3/vega-graph.html) which allows full control of the Elasticsearch query and has post-processing options
- Create a continuous [data frame transformation](https://www.elastic.co/guide/en/elastic-stack-overview/7.3/ml-dataframes.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2019, 2:42pm UTC](https://discuss.elastic.co/t/kibana-data-table-split-row-on-string-with-pipe-seperator/196964/3 "2019-09-25T14:42:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
