# Compare data from multiple rows

**URL:** <https://discuss.elastic.co/t/compare-data-from-multiple-rows/194252>\
**Category:** Kibana\
**Created:** [August 7, 2019, 2:02pm UTC](https://discuss.elastic.co/t/compare-data-from-multiple-rows/194252 "2019-08-07T14:02:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![krattan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krattan/32/51883_2.png) [@krattan](https://discuss.elastic.co/u/krattan)\
**Post date:** [August 7, 2019, 2:02pm UTC](https://discuss.elastic.co/t/compare-data-from-multiple-rows/194252/1 "2019-08-07T14:02:53Z")

</div>

is it possible in kibana scripted fields to compare data from multiple rows.

I have two search results

```auto
1. message = "abs" timestamp="hh.mm.ss" source="xyz"
2. message = "bsa" timestamp="hh.mm.ss" source="xyz"

```

`source` is same but different messages and difference timestamps. i would like to show the `timestamp difference` between these two timestamps when these messages were generated.

i have tried using painless scripting language but not sure how can i merge inputs from multiple rows.

I have multiple use cases similar to this where i have fetch data from multiple rows and do some logical operations and finally show the status like "Pass" or "fail" on each row. Please help.

These fields have to be later shown on visualizations.

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [August 7, 2019, 2:33pm UTC](https://discuss.elastic.co/t/compare-data-from-multiple-rows/194252/2 "2019-08-07T14:33:05Z")

</div>

No, You can only compare values inside the same document  
Have a look at logstash [Aggregate filter plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate)

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [August 7, 2019, 5:24pm UTC](https://discuss.elastic.co/t/compare-data-from-multiple-rows/194252/3 "2019-08-07T17:24:12Z")

</div>

It depends on the context. You can do this in:

- The metric aggregation context [https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-metric-agg-map-context.html](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-metric-agg-map-context.html)
- Bucket script aggregation contexts [https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-bucket-script-agg-context.html](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-bucket-script-agg-context.html)

I would also recommend that if you are doing this kind of analysis frequently, you should reindex this data in a way that is more suited to this kind of query. This might be using either:

- Ingest pipelines [https://www.elastic.co/guide/en/elasticsearch/reference/7.3/script-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/script-processor.html)
- Logstash
- Using the free basic-licensed Data Frame transforms [https://www.elastic.co/guide/en/kibana/current/creating-df-kib.html](https://www.elastic.co/guide/en/kibana/current/creating-df-kib.html)

---

<div class="post-metadata">

**Author:** ![krattan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krattan/32/51883_2.png) [@krattan](https://discuss.elastic.co/u/krattan)\
**Post date:** [August 8, 2019, 4:52pm UTC](https://discuss.elastic.co/t/compare-data-from-multiple-rows/194252/4 "2019-08-08T16:52:32Z")

</div>

so there is no way to calculate the time difference. ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 5, 2019, 4:52pm UTC](https://discuss.elastic.co/t/compare-data-from-multiple-rows/194252/5 "2019-09-05T16:52:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
