如何在Kibana中基于相似记录的子串数据绘制饼图可视化?
Got it, let's walk through how to get that pie chart set up step by step—you've already got the filtered data, so we're halfway there!
Step 1: Lock in your filtered context and launch the visualization tool
- First, make sure you’re still in Kibana’s Discover tab with your active filter (messages containing "I wish to go to") applied.
- Head to the top navigation bar, click Visualize Library, then hit Create visualization and select the Pie chart type.
Step 2: Connect your filtered dataset
- In the "New pie" setup screen, pick the index pattern that holds your message data.
- Next, in the left-side Filters panel, either add the same filter you used in Discover (to ensure only the relevant records are included) or copy/paste the existing filter from Discover directly.
Step 3: Extract the substring inside asterisks (two approaches)
You need to pull out the text wrapped in * from your message field—here are two reliable ways to do this:
Approach A: Create a reusable scripted field (best for future use)
- Jump to Stack Management > Index Patterns, find your target index pattern, then go to Scripted fields > Add scripted field.
- Name the field something descriptive, like
target_destination. - Set the script type to Painless, then paste this logic (replace
message.keywordwith your actual message field name):def raw_message = doc['message.keyword'].value; def pattern_matcher = /\*(.*?)\*/.matcher(raw_message); if (pattern_matcher.find()) { return pattern_matcher.group(1); } else { return null; // Mark records without * as null to exclude later } - Save the field, then go back to your visualization and refresh the field list to see the new scripted field.
Approach B: Use a one-off script in the aggregation (quick for one-time use)
- In the visualization’s Buckets panel, click Add > Split slices.
- Choose Terms as the aggregation type. For the field, select Custom label and click Edit to open the script editor. Paste this:
def msg = doc['message.keyword'].value; def match = /\*(.*?)\*/.matcher(msg); return match.find() ? match.group(1) : "No matching substring"; - Again, replace
message.keywordwith your actual message field (use the.keywordsuffix if your field is a text type to avoid partial matches).
Step 4: Clean up the data and configure the aggregation
- For either approach, in the Terms aggregation settings:
- Set Order by to Count (descending) to prioritize the most frequent substrings.
- Adjust Size to show as many top results as you need.
- Add a filter to exclude null or "No matching substring" entries: Go to the Filters panel, add a filter that excludes
target_destination: null(Approach A) or excludes the "No matching substring" value (Approach B). This ensures your pie chart only includes valid, extracted substrings.
Step 5: Polish and save your pie chart
- Switch to the Options tab to tweak the chart’s appearance: Turn on percentage labels, adjust color schemes, or add a legend if needed.
- Once you’re happy with how the data looks, click Save at the top, give your visualization a clear name (like "Destination Wishlist Distribution"), and you’re done—you can even add this to a dashboard later!
内容的提问来源于stack exchange,提问作者Anish
相关产品推荐
相关产品推荐

