# Use of regular expression in the Kibana Visualization

**URL:** https://discuss.elastic.co/t/use-of-regular-expression-in-the-kibana-visualization/207546
**Category:** Kibana
**Created:** [November 12, 2019, 3:06pm UTC](https://discuss.elastic.co/t/use-of-regular-expression-in-the-kibana-visualization/207546 "2019-11-12T15:06:40Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![AshishC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashishc/32/45312_2.png) [@AshishC](https://discuss.elastic.co/u/AshishC)
#### Post date: [November 12, 2019, 3:06pm UTC](https://discuss.elastic.co/t/use-of-regular-expression-in-the-kibana-visualization/207546/1 "2019-11-12T15:06:40Z")

</div>

Hi,

I am trying to create a dashboard to display top 10 URL hits using access log. In order to do this, I have created a visualization of the type 'Data Table'.

**Data Table Setting** :  
Metrics : Count  
Buckets : Split Rows  
Aggregation : Terms  
Field: URL  
Oder By: metric : Count

**Resulted visualization**

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/4/14c7e5f4e77349231a69657f340f28932bb2f26b.png) URL Count  
GET /services/cdc/data/92143/json HTTP/1.1 1,475  
GET /services/cdc/dataTopics/3492/json HTTP/1.1 1,462  
GET /services/cdc/dataTopics/100962/details/json HTTP/1.1 1,223  
GET /services/cdc/dataTopics/100773/details/json HTTP/1.1 1,220  
GET /services/cdc/dataTopics/94019/details/json HTTP/1.1 1,198  
GET /services/cdc/dataTopics/96093/details/json HTTP/1.1 1,196  
GET /services/cdc/dataTopics/100787/details/json HTTP/1.1 1,191  
GET /services/cdc/dataTopics/94068/details/json HTTP/1.1 1,189  
GET /services/cdc/dataTopics/94311/details/json HTTP/1.1 1,189  
GET /services/cdc/dataTopics/92937/details/json HTTP/1.1 1,188

But, I would like to aggregate highlighted URLs into single data line, something like below:

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/9/d93f8668a18a5a5a34c628937925e92fc4c082ed.png) URL Count  
GET /services/cdc/data/92143/json HTTP/1.1 1,475  
GET /services/cdc/dataTopics/3492/json HTTP/1.1 1,462  
GET /services/cdc/dataTopics/xxxxxx/details/json HTTP/1.1 9,594

Other two things I like to do is:

1. Split the URL into two columns namely verb and endpoints

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/8/1866e8b2d52038cc6e81efbabce935ab92ab57b1.png) Verb URI Count  
GET /services/cdc/data/92143/json 1,475  
GET /services/cdc/dataTopics/3492/json 1,462  
GET /services/cdc/dataTopics/xxxxxx/details/json 9,594

1. Divide the Count value by Time Range, for example, if select range is last 1 hour and divide the column value by 3600

![image](https://us1.discourse-cdn.com/elastic/original/3X/6/e/6e8bcfab1486d671f44d20a93174ce0b1ec710da.png) Verb URI Count  
GET /services/cdc/data/92143/json 0.41  
GET /services/cdc/dataTopics/3492/json 0.41  
GET /services/cdc/dataTopics/xxxxxx/details/json 2.67

---

<div class="post-metadata">

### Author: ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)
#### Post date: [November 12, 2019, 5:09pm UTC](https://discuss.elastic.co/t/use-of-regular-expression-in-the-kibana-visualization/207546/2 "2019-11-12T17:09:48Z")

</div>

The Terms aggregation only works on Keyword fields, which are exact strings. However, you may be able to use a scripted term to rewrite the values. You can do this in the Advanced setting for your visualization:

[https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-script](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-script)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 10, 2019, 5:09pm UTC](https://discuss.elastic.co/t/use-of-regular-expression-in-the-kibana-visualization/207546/3 "2019-12-10T17:09:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
