# Not able to create visualization

**URL:** <https://discuss.elastic.co/t/not-able-to-create-visualization/192223>\
**Category:** Kibana\
**Created:** [July 25, 2019, 10:50am UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223 "2019-07-25T10:50:17Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 25, 2019, 10:50am UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223/1 "2019-07-25T10:50:18Z")

</div>

Hi All,

I have extracted certain fields from the message through the GROK pattern in logstash. And the fields are available in kibana after indexing. But I am not able to use those fields to create a visualization.

Could someone help me how can I make use of the fields I have extracted to create a visualization in Kibana.

---

<div class="post-metadata">

**Author:** ![dgonzalezp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dgonzalezp/32/50804_2.png) [@dgonzalezp](https://discuss.elastic.co/u/dgonzalezp)\
**Post date:** [July 25, 2019, 11:55am UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223/2 "2019-07-25T11:55:42Z")

</div>

Hi @premkumar  
Have you refreshed the field list in the Index Pattern?  
If you dont, in Kibana go to Management\>Index Patterns\>(select your index pattern)  
And click the refresh button:  
 ![Captura](https://us1.discourse-cdn.com/elastic/original/3X/0/8/0809e9c53fc4682308348733351f6bcd46ba9780.png)

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 25, 2019, 11:58am UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223/3 "2019-07-25T11:58:14Z")

</div>

Hi @dgonzalezp,

Yes I have refreshed and I could see the fields extracted via GROK pattern in logstash. But still, not able to query the fields extracted.

For example, I have a field named Authentication status which has two types of values 200 & 400. I want to create a visualization based on the % of 200 & 400 or the count of 200 & 400 status codes.

But not able to query the fields based on the values.

---

<div class="post-metadata">

**Author:** ![dgonzalezp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dgonzalezp/32/50804_2.png) [@dgonzalezp](https://discuss.elastic.co/u/dgonzalezp)\
**Post date:** [July 25, 2019, 12:12pm UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223/4 "2019-07-25T12:12:41Z")

</div>

Could be because the vaule is a string type and you need number type to make that visualization.  
Im not sure but you can check that in the Index Pattern:

Example:

 ![Captura](https://us1.discourse-cdn.com/elastic/original/3X/2/a/2a1760ba50aa96bba9f547722f5a1ab0fe18221e.png)

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 25, 2019, 12:27pm UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223/5 "2019-07-25T12:27:03Z")

</div>

On checking the field type, it is set to type as text. But it is set automatically while extracting via the GROK pattern.  
Would you be able to shed light on setting the type while extracting the pattern?

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/7/471e29efea89fe14966e8a3cd7574f43560c4266.png)

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 25, 2019, 12:28pm UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223/6 "2019-07-25T12:28:27Z")

</div>

Yes in Kibana management I could see it as String. But I did not set the data type while extracting it.  
Is there a way to change it now or anyways to set the type while extracting?

---

<div class="post-metadata">

**Author:** ![dgonzalezp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dgonzalezp/32/50804_2.png) [@dgonzalezp](https://discuss.elastic.co/u/dgonzalezp)\
**Post date:** [July 25, 2019, 12:34pm UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223/7 "2019-07-25T12:34:02Z")

</div>

Yes you can change the data type in the filter of Logstash.  
For example I did it with "mutate" like this:

> if "mem" in [message] {  
> grok {  
> match =\> [  
> "message",  
> "mem":(?\<uso\_memoria\>([^"]\*)),"  
> ]  
> }  
> mutate {  
> convert =\> { "uso\_memoria" =\> "integer" }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 25, 2019, 12:46pm UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223/8 "2019-07-25T12:46:08Z")

</div>

Got it. Thanks @dgonzalezp

---

<div class="post-metadata">

**Author:** ![dgonzalezp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dgonzalezp/32/50804_2.png) [@dgonzalezp](https://discuss.elastic.co/u/dgonzalezp)\
**Post date:** [July 25, 2019, 12:50pm UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223/9 "2019-07-25T12:50:57Z")

</div>

You are welcome @premkumar if you could select the reply as the solution would be great.  
Have a nice day.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2019, 12:51pm UTC](https://discuss.elastic.co/t/not-able-to-create-visualization/192223/10 "2019-08-22T12:51:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
