# Aggregate on field value

**URL:** <https://discuss.elastic.co/t/aggregate-on-field-value/307968>\
**Category:** Elasticsearch\
**Created:** [June 23, 2022, 8:56am UTC](https://discuss.elastic.co/t/aggregate-on-field-value/307968 "2022-06-23T08:56:28Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![zoriax](https://avatars.discourse-cdn.com/v4/letter/z/b5e925/32.png) [@zoriax](https://discuss.elastic.co/u/zoriax)\
**Post date:** [June 23, 2022, 8:56am UTC](https://discuss.elastic.co/t/aggregate-on-field-value/307968/1 "2022-06-23T08:56:28Z")

</div>

Hello,

I'm new on this forum and I need your help 🙂

I'm looking for a we to "aggregate" values on a field. Let me explain what I'm looking for :

I have documents with this kind of fields :

```auto
{
  "_id" : "123",
  "myfield" : "test_def",
  "source.ip": "1.2.3.4"
}
{
  "_id" : "456",
  "myfield" : "test_abc",
  "source.ip": "1.2.3.4"
}
{
  "_id" : "789",
  "myfield" : "test_abc",
  "source.ip": "5.4.3.2"
}

```

What is easy to do with lens is something like that (with a table) :

```auto
source.ip (count)test_abc (count)test_def
1.2.3.4 1 1
5.4.3.2 1 -

```

What I need now is to keep only source.ip with myfield having value test\_abc **and** test\_def and exclude the rest.

```auto
source.ip (count)test_abc (count)test_def
1.2.3.4 1 1

```

I'm sure it's easy to do but I can't find any correct example for that 🙂 ! So your help here would be appreciate !

Many thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2022, 8:56am UTC](https://discuss.elastic.co/t/aggregate-on-field-value/307968/2 "2022-07-21T08:56:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
