# Visualizations based on values

**URL:** <https://discuss.elastic.co/t/visualizations-based-on-values/257466>\
**Category:** Kibana\
**Created:** [December 3, 2020, 8:29am UTC](https://discuss.elastic.co/t/visualizations-based-on-values/257466 "2020-12-03T08:29:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Niranjan\_Acharya](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/niranjan_acharya/32/80150_2.png) [@Niranjan\_Acharya](https://discuss.elastic.co/u/Niranjan_Acharya)\
**Post date:** [December 3, 2020, 8:29am UTC](https://discuss.elastic.co/t/visualizations-based-on-values/257466/1 "2020-12-03T08:29:52Z")

</div>

Hello all

I am trying to create a visualization based on AWS logs, where I want to count the number of hits on a specific host. the host information is within the json as below.

I tried all possible ways, but I cannot retrieve the host names (which is at `Preformatted text`{ name: "Host", value: "[host.com](http://host.com)" }`Preformatted text`)

below is the full record. request your suggestions and help in this

> Blockquote  
> {  
> "\_index": "wazuh-alerts-4.xxxxxxxx",  
> "\_type": "\_doc",  
> "\_id": "fkjsdlfjortiwur",  
> "\_version": 1,  
> "\_score": null,  
> "\_source": {  
> "input": {  
> "type": "log"  
> },  
> "agent": {  
> "name": "wazuh",  
> "id": "000"  
> },  
> "manager": {  
> "name": "wazuh"  
> },  
> "data": {  
> "integration": "aws",  
> "aws": {  
> "terminatingRuleId": "CyberSecurityCloudInc-CyberSecurityCloud-HighSecurityOWASPSet-",  
> "terminatingRuleType": "MANAGED\_RULE\_GROUP",  
> "log\_info": {  
> "s3bucket": "bucket",  
> "log\_file": "log\_file"  
> },  
> "ruleGroupList": [  
> {  
> "excludedRules": null,  
> "terminatingRule": null,  
> "nonTerminatingMatchingRules": ,  
> "ruleGroupId": "AWS#AWSManagedRulesAmazonIpReputationList"  
> },  
> {  
> "excludedRules": null,  
> "terminatingRule": {  
> "ruleMatchDetails": null,  
> "action": "BLOCK",  
> "ruleId": "suspicious\_access-url-001"  
> },  
> "nonTerminatingMatchingRules": ,  
> "ruleGroupId": "Cyber Security Cloud Inc.#CyberSecurityCloud-HighSecurityOWASPSet-"  
> }  
> ],  
> "httpSourceId": "httpSourceID",  
> "source": "source",  
> "webaclId": "awebaclId",  
> "action": "BLOCK",  
> "rateBasedRuleList": ,  
> "httpRequest": {  
> "country": "CO",  
> "headers": [  
> {  
> "name": "Host",  
> "value": "[host.com](http://host.com)"  
> },  
> {  
> "name": "Accept-Encoding",  
> "value": "identity"  
> },  
> {  
> "name": "User-Agent",  
> "value": "Mozilla/5.0 (iPhone; CPU iPhone OS 6\_0 like Mac OS X)"  
> }  
> ],  
> "httpVersion": "HTTP/1.1",  
> "requestId": "requestId",  
> "clientIp": "1.1.1.1",  
> "httpMethod": "GET",  
> "uri": "/.git//index"  
> },  
> "httpSourceName": "SN",  
> "nonTerminatingMatchingRules": ,  
> "formatVersion": "1",  
> "terminatingRuleMatchDetails": ,  
> "timestamp": "1606978681385.000000"  
> }  
> },  
> "rule": {  
> "firedtimes": 1,  
> "mail": false,  
> "level": 3,  
> "description": "description",  
> "groups": [  
> "group"  
> ],  
> "id": "11111"  
> },  
> "location": "location",  
> "decoder": {  
> "name": "json"  
> },  
> "id": "1606978871.6364322991",  
> "timestamp": "2020-12-03T10:01:11.913+0300"  
> },  
> "fields": {  
> "timestamp": [  
> "2020-12-03T07:01:11.913Z"  
> ]  
> },  
> "highlight": {  
> "manager.name": [  
> "@kibana-highlighted-field@wazuh@/kibana-highlighted-field@"  
> ],  
> "data.aws.httpRequest.headers.value": [  
> "@kibana-highlighted-field@field@/kibana-highlighted-field@"  
> ]  
> },  
> "sort": [  
> 1606978871913  
> ]  
> }

> Blockquote

---

<div class="post-metadata">

**Author:** ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)\
**Post date:** [December 3, 2020, 11:14am UTC](https://discuss.elastic.co/t/visualizations-based-on-values/257466/2 "2020-12-03T11:14:53Z")

</div>

Hi @Niranjan_Acharya,

I'd suggest first to injest you data differently.  
It would be easier to analyze your data if you'd have a separate `host` field in you documents:  
for example:

```auto
{
 "headers.raw": [
{
"name": "Host",
"value": "host.com"
}...],
 headers.host: "host.com"
}

```

You can pre-process documents before indexing using ingest node: [https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ingest-node.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ingest-node.html)

If it is not possible to add these fields during ingestion, then you could try to extract them using [scripted fields](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2020, 11:15am UTC](https://discuss.elastic.co/t/visualizations-based-on-values/257466/3 "2020-12-31T11:15:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
