# Complex(Dynamic) query - Using the value of a particular field in the logs to filter the logs

**URL:** <https://discuss.elastic.co/t/complex-dynamic-query-using-the-value-of-a-particular-field-in-the-logs-to-filter-the-logs/245025>\
**Category:** Kibana\
**Created:** [August 14, 2020, 2:04pm UTC](https://discuss.elastic.co/t/complex-dynamic-query-using-the-value-of-a-particular-field-in-the-logs-to-filter-the-logs/245025 "2020-08-14T14:04:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![riyag](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@riyag](https://discuss.elastic.co/u/riyag)\
**Post date:** [August 14, 2020, 2:04pm UTC](https://discuss.elastic.co/t/complex-dynamic-query-using-the-value-of-a-particular-field-in-the-logs-to-filter-the-logs/245025/1 "2020-08-14T14:04:12Z")

</div>

![Screenshot 2020-08-14 at 7.26.47 PM](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff49097a551110d57cede6d5765eb50da827c351.png)

I have logs in the above format.  
The '_key1_' "A" changes to "B" ('_key2_') and this change is documented in the log highlighted in green. After this step, "B" becomes the new value of "A" and the further logs have "B" in the '_key1_' field.  
I want to have a query where in I can find what value A has changed to("B" in this case) and filter for logs having "A" or "B" in the '_key1_' field

The filtered logs should look like

 ![Screenshot 2020-08-14 at 7.31.39 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/6/76d5c72c9e6509e25f4c064fc3c17da689fa7ab5.png)

How can this be achieved?  
Thank you!

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 18, 2020, 8:25am UTC](https://discuss.elastic.co/t/complex-dynamic-query-using-the-value-of-a-particular-field-in-the-logs-to-filter-the-logs/245025/2 "2020-08-18T08:25:56Z")

</div>

I'm not sure I fully understand your question, when you are using Discover you can simply enter this query in the search bar using KQL:

 ![Screenshot 2020-08-18 at 10.25.18](https://us1.discourse-cdn.com/elastic/original/3X/2/3/234e1864523dde1a50feec7f905ee60f53099d4e.png)

---

<div class="post-metadata">

**Author:** ![riyag](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@riyag](https://discuss.elastic.co/u/riyag)\
**Post date:** [August 19, 2020, 10:03am UTC](https://discuss.elastic.co/t/complex-dynamic-query-using-the-value-of-a-particular-field-in-the-logs-to-filter-the-logs/245025/3 "2020-08-19T10:03:06Z")

</div>

The question is, I need to be able to find what B is (this is not known beforehand).  
A turns into a value called B , the value of B can be found using one log that highlighted in green.  
So my query should be consists of :

1. Find what A has turned into (B in the example)
2. Query for logs having key1 as A or B.

I need help with the first point.

Once I get that information I can use B to make a query as you mentioned.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 19, 2020, 12:56pm UTC](https://discuss.elastic.co/t/complex-dynamic-query-using-the-value-of-a-particular-field-in-the-logs-to-filter-the-logs/245025/4 "2020-08-19T12:56:52Z")

</div>

Kibana is currently not able to do dependent queries automatically which would be necessary for a feature like this (fetch data to get "B", then fetch the actual data).

It might be possible using Canvas, but I'm not sure whether this is a good approach to your problem. Can you elaborate why exactly you have to do this? Maybe there is a way to change how your data is stored in Elasticsearch that makes it easier to query your data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2020, 12:57pm UTC](https://discuss.elastic.co/t/complex-dynamic-query-using-the-value-of-a-particular-field-in-the-logs-to-filter-the-logs/245025/5 "2020-09-16T12:57:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
