# Kibana pattern

**URL:** <https://discuss.elastic.co/t/kibana-pattern/370682>\
**Category:** Kibana\
**Created:** [November 18, 2024, 8:59am UTC](https://discuss.elastic.co/t/kibana-pattern/370682 "2024-11-18T08:59:54Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![FJT](https://avatars.discourse-cdn.com/v4/letter/f/59ef9b/32.png) [@FJT](https://discuss.elastic.co/u/FJT)\
**Post date:** [November 18, 2024, 8:59am UTC](https://discuss.elastic.co/t/kibana-pattern/370682/1 "2024-11-18T08:59:54Z")

</div>

Please help this poor guy. Another day of upping this. hoping someone can help me.

This is what it looks like in my visualization. I cannot create a pattern in my logstash cause as you know error logs have so many. So I want to have like that pattern that can identify it and count them as a category.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d221d1924a2a92d452b4607608f030864d70c03d.png)

Here is the pattern in discover that I want to like imatate in my visualization.

 ![Screenshot_2](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b4d402d5cad7f1986b66db326fe9f1fc70c0c1f.png)

I also tried a job at machine learning but nothing is showing and I cannot use it in my visualization

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/ee26dceac84192f15bc2182b56e15b02c8a0f8a9.png)

---

<div class="post-metadata">

**Author:** ![Maretti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maretti/32/118976_2.png) [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Post date:** [November 19, 2024, 2:35pm UTC](https://discuss.elastic.co/t/kibana-pattern/370682/2 "2024-11-19T14:35:21Z")

</div>

What exactly are you trying to do?

---

<div class="post-metadata">

**Author:** ![FJT](https://avatars.discourse-cdn.com/v4/letter/f/59ef9b/32.png) [@FJT](https://discuss.elastic.co/u/FJT)\
**Post date:** [November 20, 2024, 12:40am UTC](https://discuss.elastic.co/t/kibana-pattern/370682/3 "2024-11-20T00:40:36Z")

</div>

To have like a pattern in my visualization or dashboard. Something that it can identify the pattern of error message so it can count them as one category or group cause as you can see they are being count as individual which should be count as a group or category.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d221d1924a2a92d452b4607608f030864d70c03d.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 20, 2024, 1:01am UTC](https://discuss.elastic.co/t/kibana-pattern/370682/4 "2024-11-20T01:01:32Z")

</div>

What do you mean when you say _pattern_? It is confusing.

You mean to parse your message and have the information in different fields, like one field with `/usr/sbin/mysqld`, another with `mysqld` other with the version `8.2.0` and other with the process id?

If so you need to parse your message before indexing it, in Logstash or using an Elasticsearch ingest pipeline.

> [@FJT](#):
>
> I cannot create a pattern in my logstash cause as you know error logs have so many

If you have different log patterns, you need to create one parse for each log type.

---

<div class="post-metadata">

**Author:** ![FJT](https://avatars.discourse-cdn.com/v4/letter/f/59ef9b/32.png) [@FJT](https://discuss.elastic.co/u/FJT)\
**Post date:** [November 20, 2024, 1:10am UTC](https://discuss.elastic.co/t/kibana-pattern/370682/5 "2024-11-20T01:10:29Z")

</div>

Thank you for replying @leandrojmp  
This is the pattern that I mean that I want to do in my visualization also.

 ![pattern](https://us1.discourse-cdn.com/elastic/original/3X/9/1/9105cde164b9d3b276a2fdd718d4bebfcf12a65b.png)

and yes if I know that I can parse them but there are too many logs that I need to parse.Like what if there is new kind of logs that can't be parse by what I declare in logstash. Cause error message have many different structures so it was hard to declare them one by one.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 20, 2024, 2:05am UTC](https://discuss.elastic.co/t/kibana-pattern/370682/6 "2024-11-20T02:05:43Z")

</div>

> [@FJT](#):
>
> and yes if I know that I can parse them but there are too many logs that I need to parse.Like what if there is new kind of logs that can't be parse by what I declare in logstash. Cause error message have many different structures so it was hard to declare them one by one.

But this is how this works, if you have a message that does not match your current patterns to parse it, you will need to create a new pattern that will match this new message format.

If you want to use part of a message as a field in visualization or queries, then you need to parse the message and create the field.

Elastic provides hundreds of integrations for the Elastic Agent with ingest pipelines that have patterns to parse a lot of different kinds of messages as you can check [here](https://www.elastic.co/docs/current/integrations).

But if you are using Logstash, you will need to build your own pipelines with the patterns to parse your messages.

The Kibana Pattern in Discover is used to help you understand your unstructured messages and then use this information to build a pattern to parse it.

---

<div class="post-metadata">

**Author:** ![FJT](https://avatars.discourse-cdn.com/v4/letter/f/59ef9b/32.png) [@FJT](https://discuss.elastic.co/u/FJT)\
**Post date:** [November 20, 2024, 5:46am UTC](https://discuss.elastic.co/t/kibana-pattern/370682/7 "2024-11-20T05:46:43Z")

</div>

Thank you very much @leandrojmp for replying it is now clear that I cannot use pattern in my visualization aside from specifying the pattern in logstash. Yes I am not using a modules or built-in as it was also have more restriction in our desired visualization. But lastly how about using a categorization in anomaly detection at machine learning, can't I use that alternatively?
