# Timelion escape character for field name

**URL:** <https://discuss.elastic.co/t/timelion-escape-character-for-field-name/83966>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [April 28, 2017, 5:37am UTC](https://discuss.elastic.co/t/timelion-escape-character-for-field-name/83966 "2017-04-28T05:37:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aymeric\_Caroff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aymeric_caroff/32/86152_2.png) [@Aymeric\_Caroff](https://discuss.elastic.co/u/Aymeric_Caroff)\
**Post date:** [April 28, 2017, 5:37am UTC](https://discuss.elastic.co/t/timelion-escape-character-for-field-name/83966/1 "2017-04-28T05:37:03Z")

</div>

Hi,

I'm trying to make a cumulative sum in Timelion (using the latest ES and Kibana). The problem I have is that it seems that Timelion truncates the name of the field I want to sum because the field name contains a colon ( : ).

This is my expression:  
`.es(index=myindex, metric='sum:kmeta\:Size', timefield='kmeta:updateTime').cusum()`

But what I see in the debug console is this:  
Request:  
`{"sheet":[".es(index=myindex, metric='sum:kmeta\\:Size', timefield='kmeta:updateTime', offset=-50M)"],"time":{"from":"now-5y","to":"now","mode":"quick","interval":"auto","timezone":"Europe/Berlin"}}`

Response:  
`{"sheet":[{"type":"seriesList","list":[{"data":[[1335045600000,0],...,[1492898400000,0]],"type":"series","fit":"nearest","label":"q:* > sum(kmeta\\)"}]}],"stats":{"invokeTime":1493356902258,"queryCount":1,"queryTime":1493356902276,"cacheCount":1,"sheetTime":1493356902279}}`

Is there a character other than a backslash that would allow to escape the colon in the field name?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [April 28, 2017, 7:33pm UTC](https://discuss.elastic.co/t/timelion-escape-character-for-field-name/83966/2 "2017-04-28T19:33:14Z")

</div>

Elasticsearch can store objects of data, so if you have fields that are metadata, you will be much better off structuring the data as:

```auto
{
  "kMeta": {
    "Size": 1234,
    "updateTime": <time_value>
  },
  <other_values>
}

```

The expression would then look like:

```auto
.es(index=myindex, metric='sum:kmeta.Size', timefield='kmeta.updateTime').cusum()

```

I don't know offhand if there is a way to escape the colon to work with it as it is, but I strongly suggest this is a data modeling problem.

---

<div class="post-metadata">

**Author:** ![Aymeric\_Caroff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aymeric_caroff/32/86152_2.png) [@Aymeric\_Caroff](https://discuss.elastic.co/u/Aymeric_Caroff)\
**Post date:** [April 29, 2017, 8:25pm UTC](https://discuss.elastic.co/t/timelion-escape-character-for-field-name/83966/3 "2017-04-29T20:25:27Z")

</div>

Hi Tim, thanks for the answer.

Yes I agree that the data could/should have been modeled in the way you suggested. Unfortunately, the data comes from a legacy app and the cost of migrating the data to the new model is just way too high.  
In addition, Lucene query syntax (used in Elasticsearch and Kibana) supports escaping the colon so I'm surprised to see that Timelion doesn't.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2017, 8:27pm UTC](https://discuss.elastic.co/t/timelion-escape-character-for-field-name/83966/4 "2017-05-27T20:27:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
