# Time Series Visual Builder - regexing top n field responses

**URL:** <https://discuss.elastic.co/t/time-series-visual-builder-regexing-top-n-field-responses/245582>\
**Category:** Kibana\
**Created:** [August 19, 2020, 10:32am UTC](https://discuss.elastic.co/t/time-series-visual-builder-regexing-top-n-field-responses/245582 "2020-08-19T10:32:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcus\_Webb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcus_webb/32/74092_2.png) [@Marcus\_Webb](https://discuss.elastic.co/u/Marcus_Webb)\
**Post date:** [August 19, 2020, 10:32am UTC](https://discuss.elastic.co/t/time-series-visual-builder-regexing-top-n-field-responses/245582/1 "2020-08-19T10:32:54Z")

</div>

Hi Guys

I know that the Timelion feature is being deprecated so I'm learning TSVB and fast. My question is this:

I have a field called `responsefield` which contains literally thousands of possibilities, as there are variable factors in there, such as an IP address or an ISP name, or a rule that an ISP has applied to a message that we have sent them. What I would like to be able to do is to count up the possible responses that we search for and count them.

As an example I'd like  
`smtp;421 4.7.0 [TSS04] Messages from a.b.c.d temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html`  
and  
`smtp;421 4.7.4 [TSS07] Messages from e.f.g.h temporarily deferred due to user complaints - 4.16.55.2; see https://help.yahoo.com/kb/postmaster/SLN1234.html`

to be counted as the same thing. The following should also be grouped as one type:  
` smtp;451 4.4.4 Temporary server error. Please try again later ATTR5 [HE1EUR02FT016.eop-EUR02.prod.protection.outlook.com]`  
and  
`smtp;451 4.4.4 Temporary server error. Please try again later ATTR5 [CWLGBR01FT018.eop-gbr01.prod.protection.outlook.com]`

could someone please break this down for me so I can see how it might be achieved? I'm trying to use Group by Filters, but please tell me if this is not the best method for this.

Kind Regards  
Marcus Webb  
Pure360

---

<div class="post-metadata">

**Author:** ![myasonik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/myasonik/32/62369_2.png) [@myasonik](https://discuss.elastic.co/u/myasonik)\
**Post date:** [August 20, 2020, 9:21pm UTC](https://discuss.elastic.co/t/time-series-visual-builder-regexing-top-n-field-responses/245582/2 "2020-08-20T21:21:31Z")

</div>

If you haven't seen it yet, the query syntax docs for TSVB might be helpful to you:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#query-string-syntax](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#query-string-syntax)

It seems like what you're trying to do should be possible though maybe a little brittle.

What might be a better approach though is to create a scripted field which buckets your responses by type and then visualize or filter based on that scripted field. This should make it easier to manage, use, and reuse in the long term and you may find using Painless to be easier.

This blog post is somewhat old but still gives a decent overview and links to docs that are continually updated (just make sure to switch them to a current version):

> **[Using Painless in Kibana scripted fields](https://www.elastic.co/blog/using-painless-kibana-scripted-fields)**
>
> This blog presents common use cases for Kibana scripted fields, and walks user through how to create scripted fields in a newly set-up Elastic Cloud instance.

---

<div class="post-metadata">

**Author:** ![Marcus\_Webb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcus_webb/32/74092_2.png) [@Marcus\_Webb](https://discuss.elastic.co/u/Marcus_Webb)\
**Post date:** [August 21, 2020, 3:39pm UTC](https://discuss.elastic.co/t/time-series-visual-builder-regexing-top-n-field-responses/245582/3 "2020-08-21T15:39:26Z")

</div>

Thanks - that does help me a lot. I shall try to do some stuff with Painless (a misnomer if ever there was one) to get the results I'm looking for.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2020, 3:39pm UTC](https://discuss.elastic.co/t/time-series-visual-builder-regexing-top-n-field-responses/245582/4 "2020-09-18T15:39:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
