# Kibana visualization using wildcards

**URL:** <https://discuss.elastic.co/t/kibana-visualization-using-wildcards/320302>\
**Category:** Kibana\
**Created:** [December 1, 2022, 10:27pm UTC](https://discuss.elastic.co/t/kibana-visualization-using-wildcards/320302 "2022-12-01T22:27:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tfinan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tfinan/32/100693_2.png) [@tfinan](https://discuss.elastic.co/u/tfinan)\
**Post date:** [December 1, 2022, 10:27pm UTC](https://discuss.elastic.co/t/kibana-visualization-using-wildcards/320302/1 "2022-12-01T22:27:19Z")

</div>

Probably a very basic question here, but I am can't figure it out. I have an index with many fields  
named "process\_" with a numeric value assigned. I would like to create a table listing  
these fields, sorted by the value.  
In other words, if I have "process\_aaa"=45 and "process\_bbb"=34 and "process\_ccc"=58, I want  
to generate a table like:

```auto
process_ccc: 58
process_aaa:45
process_bbb:34

```

My problem is that I can't see to reliably get wildcard to work. They seem to work in REST API  
queries, but not in Kibana itself.

Thoughts?

Tim Finan

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [December 27, 2022, 3:05pm UTC](https://discuss.elastic.co/t/kibana-visualization-using-wildcards/320302/2 "2022-12-27T15:05:51Z")

</div>

Kibana is mostly about aggregating data, so when dealing with visualizing individual documents the options are more limited. One thing you can do is to modify your data at ingest to coerce your `process_xxx` fields into a new field and then use Discover to show those rows in a dashboard as a saved search.

The process would be like this (tested in 8.5.0):

```auto
DELETE discuss-320302

# Create an index with a field to store process numbers (if found)
# and the process field name as keyword
PUT discuss-320302
{
  "mappings": {
    "properties": {
      "ingest_process_name": { "type": "keyword"},
      "ingest_process_value": { "type": "integer"}
    }
  }, 
  "settings": {
    "number_of_replicas": 1
  }
}

# Create an ingest pipeline that will search for
# process_xxx fields and stores the field name and value
# in "ingest_process_[name,value]" separate fields
PUT _ingest/pipeline/discuss-320302-pipeline
{
  "description": "Coerces a value from similar named fields",
  "version": 1,
  "processors": [
    {
      "script": {
        "source": """
        for (key in ctx.keySet()){
          if (key.startsWith('process_')){
            ctx['ingest_process_name'] = key;
            ctx['ingest_process_value'] = ctx[key];
            break;
          }
        }
        """
      }
    }
  ]
}

# Ingest some data, including a field witouht a process_xxx
# field to test things
POST discuss-320302/_bulk?pipeline=discuss-320302-pipeline
{ "index":{}}
{ "process_aaa": 45}
{ "index":{}}
{ "process_bbb": 11}
{ "index":{}}
{ "process_ccc": 27}
{ "index":{}}
{ "process_ddd": 37}
{ "index":{}}
{ "another_thingy": 37}

# Test the results
GET discuss-320302/_search

# Create a Kibana data view
POST kbn:/api/data_views/data_view
{
  "data_view": {
     "title": "discuss-320302",
     "name": "Discuss 320302 data"
  }
}

```

After these steps you can go to Discover and point to the new Data View

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8a483ff7d3769b0726cfe6df281399030098d450.png)

Maybe this is not exactly what you want but hopefully gives you some pointers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2023, 3:06pm UTC](https://discuss.elastic.co/t/kibana-visualization-using-wildcards/320302/3 "2023-01-24T15:06:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
