# Showing all keywords matching a certain pattern

**URL:** https://discuss.elastic.co/t/showing-all-keywords-matching-a-certain-pattern/76780
**Category:** Kibana
**Created:** [February 28, 2017, 1:24pm UTC](https://discuss.elastic.co/t/showing-all-keywords-matching-a-certain-pattern/76780 "2017-02-28T13:24:57Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Cylindric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cylindric/32/5660_2.png) [@Cylindric](https://discuss.elastic.co/u/Cylindric)
#### Post date: [February 28, 2017, 1:24pm UTC](https://discuss.elastic.co/t/showing-all-keywords-matching-a-certain-pattern/76780/1 "2017-02-28T13:24:57Z")

</div>

Hi folks. I am not sure how to achieve the visualisation that I need from our web logs.

We have a bunch of URLs being logged, part of which contains a customer-identifying string.

```
/customerA/whatever.html
/customerA/something.html
/customerA/whatever.html
/customerB/something.html
/customerC/whatever.html

```

I am using a standard analyzer on the field, so I can get charts based on the tokens in there:

```
whatever.html 3
customerA 3
something.html 2
customerB 2
customerC 1

```

What I would like to get out is just the customer part as a count, where one of the other tokens is present (e.g. whatever.html)

```
customerA 2
customerC 1

```

Or e.g. something.html:

```
customerA 1
customerB 1

```

If I query on `requestUrl` it looks like it is using the whole field, not the split out parts.

I could work around this if there is a way of adding a field during ingress (these come from FileBeat into Elastic Cloud) based on a regex result, as the customer-identifying part is always matchable, in this example `customer(.*)`

---

<div class="post-metadata">

### Author: ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)
#### Post date: [February 28, 2017, 11:23pm UTC](https://discuss.elastic.co/t/showing-all-keywords-matching-a-certain-pattern/76780/2 "2017-02-28T23:23:32Z")

</div>

@Cylindric would you mind sharing the relevant mappings for the fields you're trying to create the reports using?

---

<div class="post-metadata">

### Author: ![Cylindric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cylindric/32/5660_2.png) [@Cylindric](https://discuss.elastic.co/u/Cylindric)
#### Post date: [March 1, 2017, 9:26am UTC](https://discuss.elastic.co/t/showing-all-keywords-matching-a-certain-pattern/76780/3 "2017-03-01T09:26:14Z")

</div>

Sure. Currently I have the following, but I can easily change it and recreate the indices if necessary:

```
    "requestUrl": {
      "index": "analyzed",
      "type": "string",
      "fielddata": true,
      "fields": {
        "raw": {
          "type": "string",
          "index": "not_analyzed"
        }
      }
    },
```

---

<div class="post-metadata">

### Author: ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)
#### Post date: [March 1, 2017, 5:36pm UTC](https://discuss.elastic.co/t/showing-all-keywords-matching-a-certain-pattern/76780/4 "2017-03-01T17:36:55Z")

</div>

> [@Cylindric](#):
>
> I could work around this if there is a way of adding a field during ingress

This would absolutely be the ideal way to handle this, but you can also use the advanced settings in the terms aggregation to specify a regular express that terms must match. In the below example your choose your field and set your include pattern to `customer.*`

 ![](https://us1.discourse-cdn.com/elastic/original/2X/9/9fecee5f3cbbf7806f7f4fd7bf99bfdbbbd472c5.png)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 29, 2017, 5:36pm UTC](https://discuss.elastic.co/t/showing-all-keywords-matching-a-certain-pattern/76780/5 "2017-03-29T17:36:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
