# Kibana group visualization

**URL:** <https://discuss.elastic.co/t/kibana-group-visualization/198913>\
**Category:** Kibana\
**Created:** [September 10, 2019, 1:49pm UTC](https://discuss.elastic.co/t/kibana-group-visualization/198913 "2019-09-10T13:49:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![anon42972578](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@anon42972578](https://discuss.elastic.co/u/anon42972578)\
**Post date:** [September 10, 2019, 1:49pm UTC](https://discuss.elastic.co/t/kibana-group-visualization/198913/1 "2019-09-10T13:49:43Z")

</div>

Hello,

i try to build an visualization ( vertical bar ) , where i can group my elements.

For example:

server-prod-1  
server-prod-2  
server-prod-3

--\> in legend visible as server-prod

server-test-1  
server-test-2  
server-test-3

--\> in legend visible as server-test

I already tried to do this with Exclude and added "._test-_" in exclude and group all others with the name "server-prod". But how can do the same with "server-test" now ?

the problem in this case is, that i want to use something like "._test._" and "._prod._" because i dont want to update the visualization when 50 new servers comes in.

How can I group something in a visualization ?

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [September 12, 2019, 4:59pm UTC](https://discuss.elastic.co/t/kibana-group-visualization/198913/2 "2019-09-12T16:59:30Z")

</div>

Have you tried using the Filters aggregation? You could create buckets like "server-prod-\*", "server-test-\*", etc.

---

<div class="post-metadata">

**Author:** ![anon42972578](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@anon42972578](https://discuss.elastic.co/u/anon42972578)\
**Post date:** [September 13, 2019, 7:04am UTC](https://discuss.elastic.co/t/kibana-group-visualization/198913/3 "2019-09-13T07:04:10Z")

</div>

no, i never used the filters aggregation.

i need some help with it:  
what i need to enter in it ?

"server-prod" : { "match" : { "server.type" : "server-prod-\*" }}

is not working.

The documentation has always long code snippets for Dev Tools. I may be wrong but i think this is not the right syntax or ?

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [September 13, 2019, 5:00pm UTC](https://discuss.elastic.co/t/kibana-group-visualization/198913/4 "2019-09-13T17:00:08Z")

</div>

When you create a visualization, one of the bucket aggregations that you can select is the "filters" aggregation, which allows you to specify a search for each bucket. I'm suggesting you do something like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/1/71a75684689d6b774efa2ad73a9748617c912b2a.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2019, 11:32am UTC](https://discuss.elastic.co/t/kibana-group-visualization/198913/6 "2019-10-22T11:32:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
