# Visualizations by Host include the Domain as a host

**URL:** <https://discuss.elastic.co/t/visualizations-by-host-include-the-domain-as-a-host/37809>\
**Category:** Kibana\
**Created:** [December 23, 2015, 12:06am UTC](https://discuss.elastic.co/t/visualizations-by-host-include-the-domain-as-a-host/37809 "2015-12-23T00:06:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jruybal](https://avatars.discourse-cdn.com/v4/letter/j/d07c76/32.png) [@jruybal](https://discuss.elastic.co/u/jruybal)\
**Post date:** [December 23, 2015, 12:06am UTC](https://discuss.elastic.co/t/visualizations-by-host-include-the-domain-as-a-host/37809/1 "2015-12-23T00:06:35Z")

</div>

Haven't used Kibana in a while, but I've caught on to 4 pretty quickly. The thing I cannot figure out now is this problem with visualization.

Whenever I try to stack line charts by host (or split pie charts by host) I get a list of all the hosts then the domain is listed as an extra host with a count equal to the sum of all the individual hosts.

This effectively doubles the charts and throws them off.

When I look at the raw logs each host has its full fqdn as a hostname, so I'm not sure what's going on.

There are two images below, in both cases, the purple area is the domain all other sections are individual hosts.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/edf381866cbb4730c00661cce0b3561657e782df.png) ![](https://us1.discourse-cdn.com/elastic/original/2X/6/6767272a1318eb6d2f5e8887f1b15f9bdc505fc7.png)

I'm pretty sure there's an obvious answer here, but after searching for two hours I can't find it.

* * *

#### Update

I've found one log type that doesn't do this. When I visualize it the entire fqdn for each host shows up in the Legend.

All of the others split the hostname up from the domain. However I still can't figure out why this is happening.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [December 23, 2015, 3:31am UTC](https://discuss.elastic.co/t/visualizations-by-host-include-the-domain-as-a-host/37809/2 "2015-12-23T03:31:34Z")

</div>

Hi Josh,  
I think this might help you. I thought the solution was to use not\_analyzed for your domain. But this person did something a little different but apparently worked for them.

> <https://stackoverflow.com/questions/26486037/elasticsearch-mapping-tokenizer-keyword-to-avoid-splitting-tokens-and-enable-use>

Lee

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:06pm UTC](https://discuss.elastic.co/t/visualizations-by-host-include-the-domain-as-a-host/37809/3 "2017-07-06T14:06:08Z")

</div>


