# Kibana Timelion Question Split Label More than 1 field

**URL:** <https://discuss.elastic.co/t/kibana-timelion-question-split-label-more-than-1-field/247283>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [September 2, 2020, 7:37pm UTC](https://discuss.elastic.co/t/kibana-timelion-question-split-label-more-than-1-field/247283 "2020-09-02T19:37:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gundam\_Airline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gundam_airline/32/67546_2.png) [@Gundam\_Airline](https://discuss.elastic.co/u/Gundam_Airline)\
**Post date:** [September 2, 2020, 7:37pm UTC](https://discuss.elastic.co/t/kibana-timelion-question-split-label-more-than-1-field/247283/1 "2020-09-02T19:37:44Z")

</div>

How can I split more than 1 field in the label for Timelion. I have seen multiple post that shows 1 variable as shown in the link below but nothing for 2 or more. Can someone please give me an example that could assist me?

> [@How to split lines based on a term in Timelion using split() or other?](https://discuss.elastic.co/t/how-to-split-lines-based-on-a-term-in-timelion-using-split-or-other/85851/6):
>
> You can use Regex in your label. It will be something like: .label(regex='.\* username.keyword:(.\*) \> .\*', label='$1')

Thanks

---

<div class="post-metadata">

**Author:** ![afharo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/afharo/32/75202_2.png) [@afharo](https://discuss.elastic.co/u/afharo)\
**Post date:** [September 14, 2020, 4:09pm UTC](https://discuss.elastic.co/t/kibana-timelion-question-split-label-more-than-1-field/247283/2 "2020-09-14T16:09:47Z")

</div>

Hi @Gundam_Airline,

You can declare the `split` parameter multiple times.

In the following example I'm plotting the data in the index `kibana_sample_data_logs`, splitting first by the 5 top `url.keyword` and then, by `response.keyword:3`

```auto
.es(
    index=kibana_sample_data_logs,
    split=url.keyword:5,
    split=response.keyword:3
)

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/5/853c5dda062d2749df2c7ebf7b87aa41bf3db4cc.png)

The `.label` regex you mentioned is for breaking down the text

> q:\* \> url.keyword:[https://artifacts.elastic.co/downloads/apm-server/apm-server-6.3.2-amd64.deb](https://artifacts.elastic.co/downloads/apm-server/apm-server-6.3.2-amd64.deb) \> response.keyword:404 \> count

Into something else.  
For instance, if we want to present it as  
`404 - https://artifacts.elastic.co/downloads/apm-server/apm-server-6.3.2-amd64.deb` instead, we need to apply the regex to that text as:

```auto
.label(
    regex='.* url.keyword:(.*) > response.keyword:(.*) > .*',
    label='$2 - $1'
)

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/4/84c095a7b541007f885c43f135895c48e5c2af21.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2020, 4:09pm UTC](https://discuss.elastic.co/t/kibana-timelion-question-split-label-more-than-1-field/247283/3 "2020-10-12T16:09:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
