# Aggregating by count for a particular string field

**URL:** <https://discuss.elastic.co/t/aggregating-by-count-for-a-particular-string-field/122446>\
**Category:** Kibana\
**Created:** [March 5, 2018, 7:10am UTC](https://discuss.elastic.co/t/aggregating-by-count-for-a-particular-string-field/122446 "2018-03-05T07:10:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhil\_Utane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_utane/32/27547_2.png) [@Nikhil\_Utane](https://discuss.elastic.co/u/Nikhil_Utane)\
**Post date:** [March 5, 2018, 7:10am UTC](https://discuss.elastic.co/t/aggregating-by-count-for-a-particular-string-field/122446/1 "2018-03-05T07:10:52Z")

</div>

Hi,

I have 2 separate indices across which I want to correlate few fields.  
I have created a data table visualization, added the required aggregated metrics and everything is working as expected.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/8/48a41b69f1be91bb57fe8daa3fe93908c67c1ee9.png)

Now in this case, I added integer fields so that I can use the Sum aggregation and count the number of times these have occurred.  
I also have a string field for the same purpose.  
Logstash code matching the event:

> ```
> add_field => { "l3_debug" => "RRC_CONNECTION_REQUEST"}
> add_field => { "n_rrc_conn_req" => "1"}
> 
> ```

These 2 fields are redundant. What I want to know is, in the above table, instead of using sum of 'n\_rrc\_conn\_req', can I use count of l3\_debug: RRC\_CONNECTION\_REQUEST and eliminate the integer field?  
If you select Count, then there is no option to apply any filter.  
Can the Advanced-\>JSON input section be used for this?

Thanks  
Nikhil

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [March 7, 2018, 5:29pm UTC](https://discuss.elastic.co/t/aggregating-by-count-for-a-particular-string-field/122446/2 "2018-03-07T17:29:43Z")

</div>

hi @Nikhil_Utane,

you're approach is a common work-around, because as you said, you cannot create a filter on just that count-metric.

If you want to avoid adding that field with logstash, you can use a scripted field instead. This is a dynamically computed field that runs at query-time. You'd give it a "1" value if you want to count the doc, and a "0"-value if not. Then you count by doing the sum on that field.

more info here: [https://www.elastic.co/guide/en/kibana/current/scripted-fields.html](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html)

---

<div class="post-metadata">

**Author:** ![Nikhil\_Utane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_utane/32/27547_2.png) [@Nikhil\_Utane](https://discuss.elastic.co/u/Nikhil_Utane)\
**Post date:** [March 8, 2018, 4:02am UTC](https://discuss.elastic.co/t/aggregating-by-count-for-a-particular-string-field/122446/3 "2018-03-08T04:02:57Z")

</div>

Hi Thomas,

Yes, I have used scripted fields. Thanks for your suggestion. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2018, 4:03am UTC](https://discuss.elastic.co/t/aggregating-by-count-for-a-particular-string-field/122446/4 "2018-04-05T04:03:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
