# Combine aggregated fields on Kibana visualization

**URL:** <https://discuss.elastic.co/t/combine-aggregated-fields-on-kibana-visualization/130409>\
**Category:** Kibana\
**Created:** [May 3, 2018, 9:12am UTC](https://discuss.elastic.co/t/combine-aggregated-fields-on-kibana-visualization/130409 "2018-05-03T09:12:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![madou23](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@madou23](https://discuss.elastic.co/u/madou23)\
**Post date:** [May 3, 2018, 9:12am UTC](https://discuss.elastic.co/t/combine-aggregated-fields-on-kibana-visualization/130409/1 "2018-05-03T09:12:01Z")

</div>

Hi all,  
I'm creating a line visualization in Kibana with a data histogram aggregation based on a timestamp field and I'm using a term sub-aggregation on a field called "failure" to split series. The problem is that I have some different values that imply the same type of failure like "XX8-1" and "8-1". How can I combine only these two values on a single aggregation and draw it with the other aggregations on the same visualization ?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [May 3, 2018, 1:47pm UTC](https://discuss.elastic.co/t/combine-aggregated-fields-on-kibana-visualization/130409/2 "2018-05-03T13:47:24Z")

</div>

For what you need the Filter aggregation is the answer.

You can set a list of values a failures using the filter syntax.  
This is one of my examples:  
 ![filter_agg](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3ecfb546e6d425bc1fe4c17a3168f26d8bd3183.png)

In your case it would be something like:  
`failure:XX8-1 or failure:8-1` for the first field  
`!failure:XX8-1 and !failure:8-1` for the second field if all the other possible values mean a different type of it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2018, 1:47pm UTC](https://discuss.elastic.co/t/combine-aggregated-fields-on-kibana-visualization/130409/3 "2018-05-31T13:47:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
