# Taking string as separate token while Visualizing on KIbana

**URL:** <https://discuss.elastic.co/t/taking-string-as-separate-token-while-visualizing-on-kibana/48117>\
**Category:** Kibana\
**Created:** [April 22, 2016, 5:09am UTC](https://discuss.elastic.co/t/taking-string-as-separate-token-while-visualizing-on-kibana/48117 "2016-04-22T05:09:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gaurav\_Harsola](https://avatars.discourse-cdn.com/v4/letter/g/ecc23a/32.png) [@Gaurav\_Harsola](https://discuss.elastic.co/u/Gaurav_Harsola)\
**Post date:** [April 22, 2016, 5:09am UTC](https://discuss.elastic.co/t/taking-string-as-separate-token-while-visualizing-on-kibana/48117/1 "2016-04-22T05:09:22Z")

</div>

Hi

I have country field in my elastic search index with value : san francisco,mountain view  
But when i visualize pie chart on kibana using country field then it give me chart for both 'san' and 'francisco' rather than giving single one for 'san francisco'.

Please help me out.

Thanks  
Gaurav

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 22, 2016, 5:57am UTC](https://discuss.elastic.co/t/taking-string-as-separate-token-while-visualizing-on-kibana/48117/2 "2016-04-22T05:57:25Z")

</div>

The field name is analyzed, i.e. split into tokens. The field you use for such aggregations should be non-analyzed. If you don't want to make the field itself non-analyzed you can create subfields that are non-analyzed and use _those_ for aggregations. Check the documentation.

---

<div class="post-metadata">

**Author:** ![Gaurav\_Harsola](https://avatars.discourse-cdn.com/v4/letter/g/ecc23a/32.png) [@Gaurav\_Harsola](https://discuss.elastic.co/u/Gaurav_Harsola)\
**Post date:** [April 22, 2016, 6:39am UTC](https://discuss.elastic.co/t/taking-string-as-separate-token-while-visualizing-on-kibana/48117/3 "2016-04-22T06:39:11Z")

</div>

input {  
file {  
path =\> "/home/logGenerator.log"  
start\_position =\> "beginning"  
}  
}  
filter {  
grok {  
match =\> { "message" =\> '[%{TIMESTAMP\_ISO8601:timestamp}] %{NUMBER:TxID} %{WORD:loglevel} (?\d{4}-\d{4}-\d{4}) %{BASE10NUM:amount} %{WORD:method} %{WORD:Merchant} %{NUMBER:pinCode} "(%{GREEDYDATA:msg})"'}  
}  
}

output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "fraud1"  
}  
}

Let suppose this is my conf file .How i will mention my columns as analysed or non anaylsed .  
Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 23, 2016, 6:43pm UTC](https://discuss.elastic.co/t/taking-string-as-separate-token-while-visualizing-on-kibana/48117/4 "2016-04-23T18:43:42Z")

</div>

That configuration needs to be done on the Elasticsearch side. As I said, read the documentation about mappings and index templates. I'm happy to help with questions but you have to do your part.

---

<div class="post-metadata">

**Author:** ![Gaurav\_Harsola](https://avatars.discourse-cdn.com/v4/letter/g/ecc23a/32.png) [@Gaurav\_Harsola](https://discuss.elastic.co/u/Gaurav_Harsola)\
**Post date:** [April 25, 2016, 8:38am UTC](https://discuss.elastic.co/t/taking-string-as-separate-token-while-visualizing-on-kibana/48117/5 "2016-04-25T08:38:41Z")

</div>

Thanks Magnus ! I got the solution and it is working fine.

Thanks for your support !

Regards  
Gaurav

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:55pm UTC](https://discuss.elastic.co/t/taking-string-as-separate-token-while-visualizing-on-kibana/48117/6 "2017-07-06T13:55:14Z")

</div>


