# Aggregate on where condition

**URL:** <https://discuss.elastic.co/t/aggregate-on-where-condition/45251>\
**Category:** Kibana\
**Created:** [March 23, 2016, 4:22pm UTC](https://discuss.elastic.co/t/aggregate-on-where-condition/45251 "2016-03-23T16:22:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [March 23, 2016, 4:22pm UTC](https://discuss.elastic.co/t/aggregate-on-where-condition/45251/1 "2016-03-23T16:22:05Z")

</div>

In Kibana, I can easily aggregate on "where condition1 and condition2", is there any drag and drop solution to aggregate on "where condition1 or condition2"  
The following picture is the screen shot of "and" condition. Is there any chance we can make it or by press control and select different part in the visualization pictures?

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a77cb86c840c7eff33979460f689beaca8cc1b7e.png)

Kibana can do roll up, drill down, slice, it would be good if it can do dice.

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [March 23, 2016, 4:49pm UTC](https://discuss.elastic.co/t/aggregate-on-where-condition/45251/2 "2016-03-23T16:49:58Z")

</div>

In the latest shipping version of Kibana, 4.4, you can do that in a custom filter, but not by point-and-click in UI. Instructions for that custom filter are at the end of this page in the docs: [https://www.elastic.co/guide/en/kibana/current/visualize.html](https://www.elastic.co/guide/en/kibana/current/visualize.html)

We are tracking issues to make it easier in the UI in the future:

> <https://github.com/elastic/kibana/issues/5249>

  

> <https://github.com/elastic/kibana/issues/3693>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:58pm UTC](https://discuss.elastic.co/t/aggregate-on-where-condition/45251/3 "2017-07-06T13:58:05Z")

</div>


