# Multiple lines for count of different values in one field

**URL:** <https://discuss.elastic.co/t/multiple-lines-for-count-of-different-values-in-one-field/148703>\
**Category:** Kibana\
**Created:** [September 15, 2018, 12:14pm UTC](https://discuss.elastic.co/t/multiple-lines-for-count-of-different-values-in-one-field/148703 "2018-09-15T12:14:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![What](https://avatars.discourse-cdn.com/v4/letter/w/5f9b8f/32.png) [@What](https://discuss.elastic.co/u/What)\
**Post date:** [September 15, 2018, 12:14pm UTC](https://discuss.elastic.co/t/multiple-lines-for-count-of-different-values-in-one-field/148703/1 "2018-09-15T12:14:56Z")

</div>

I have read in my Apache logfiles into Elasticsearch. They contain a field "server\_name" which specifies the domain name of the site that was visited. Possible values are "[domain-1.com](http://domain-1.com)", "[domain-2.com](http://domain-2.com)", etc. (eight domains in all).

Here is an (anonymized) example line from the original logfiles, which specifies the site as "[domain-1.com](http://domain-1.com)":

```
207.87.175.xxx - - [15/Sep/2018:00:04:49 +0800] "GET /index.html HTTP/1.1" 200 13252 www.domain-1.com "-" "Mozilla/5.0 (...)" "-"

```

I would like to create a graph with days on the x-axis and the number of entries for each day on the y-axis, with one line for each of my eight domains. Like this:

 ![kibana](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e7bbe57a884e8751ae6cf3519b040eea608e39a0.png)

I've seen some tutorials on the web, this site among them, which make use of a [Split Line](https://discuss.elastic.co/t/selecting-multiple-fields-to-display-in-a-line-graph/51081) graph that I cannot find in my version of Kibana (6.4.0).

How can I create such a graph?

I'm using Elastic Stack 6.4.0

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [September 19, 2018, 4:40pm UTC](https://discuss.elastic.co/t/multiple-lines-for-count-of-different-values-in-one-field/148703/2 "2018-09-19T16:40:55Z")

</div>

You should be able to create a line graph, then for "Buckets", you'll want to "Split Series", select "Terms" as the aggregation, and choose "server\_name" as the field, then "add sub-buckets", "X-axis", and choose "Date histogram".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 17, 2018, 4:40pm UTC](https://discuss.elastic.co/t/multiple-lines-for-count-of-different-values-in-one-field/148703/3 "2018-10-17T16:40:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
