# Add fields of Aggregated log in Visualization

**URL:** <https://discuss.elastic.co/t/add-fields-of-aggregated-log-in-visualization/132924>\
**Category:** Kibana\
**Created:** [May 23, 2018, 5:14am UTC](https://discuss.elastic.co/t/add-fields-of-aggregated-log-in-visualization/132924 "2018-05-23T05:14:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![saramali](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@saramali](https://discuss.elastic.co/u/saramali)\
**Post date:** [May 23, 2018, 5:14am UTC](https://discuss.elastic.co/t/add-fields-of-aggregated-log-in-visualization/132924/1 "2018-05-23T05:14:57Z")

</div>

Is there a way in which I can add the fields of an aggregated log.  
For example, I select a MAX aggregation on the field timestamp and the log with the maximum timestamp is selected in the data table.  
Now I want to add fields of that log with maximum timestamp. The only way is that I create a bucket on it but if the term has multiple values, it split the rows respectively. I just want to add that field like we add fields in the discover tab.  
I know I can save a search and import it in a dashboard but in search can I aggregate and select the log with Maximum timestamp? For that I have to use a data table and the only way to add field is to create a bucket on the term, adding fields of the log is much easier in search which is done without making a bucket on this field.

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [May 23, 2018, 2:37pm UTC](https://discuss.elastic.co/t/add-fields-of-aggregated-log-in-visualization/132924/2 "2018-05-23T14:37:48Z")

</div>

Hey @saramali,

I'm not sure I'm following. Can you describe what you want to do? Is it creating a data table? Or being able to construct a search?

---

<div class="post-metadata">

**Author:** ![saramali](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@saramali](https://discuss.elastic.co/u/saramali)\
**Post date:** [May 24, 2018, 4:20am UTC](https://discuss.elastic.co/t/add-fields-of-aggregated-log-in-visualization/132924/3 "2018-05-24T04:20:07Z")

</div>

I want to create a data table but for adding a term I need to create a bucket. Is there a way using which I can add a field without creating a bucket?

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [June 7, 2018, 8:36pm UTC](https://discuss.elastic.co/t/add-fields-of-aggregated-log-in-visualization/132924/4 "2018-06-07T20:36:20Z")

</div>

I don't think so. Visualizations are designed to display aggregated data. You might want to look into [using Time Series Visual Builder](https://www.elastic.co/guide/en/kibana/current/time-series-visual-builder.html) as that is intended to solve other use cases.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2018, 8:36pm UTC](https://discuss.elastic.co/t/add-fields-of-aggregated-log-in-visualization/132924/5 "2018-07-05T20:36:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
