# Complex multi line condition based aggregation - kibana

**URL:** <https://discuss.elastic.co/t/complex-multi-line-condition-based-aggregation-kibana/280054>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [July 30, 2021, 8:01am UTC](https://discuss.elastic.co/t/complex-multi-line-condition-based-aggregation-kibana/280054 "2021-07-30T08:01:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Riyas\_Siddikk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/riyas_siddikk/32/92344_2.png) [@Riyas\_Siddikk](https://discuss.elastic.co/u/Riyas_Siddikk)\
**Post date:** [July 30, 2021, 8:01am UTC](https://discuss.elastic.co/t/complex-multi-line-condition-based-aggregation-kibana/280054/1 "2021-07-30T08:01:27Z")

</div>

0

I have 6 csv documents as below which is marked under same index:

```auto
Doc 1 - 2021-07-30 11:45:56.731,46,2001,2134566,CHARGEABLE
Doc 2 - 2021-07-30 11:45:56.752,67,2001,2134566,XXX
Doc 3 - 2021-07-30 11:45:56.754,46,2002,2134566,CHARGEABLE
Doc 4 - 2021-07-30 11:45:57.432,47,2001,2134566,CHARGEABLE
Doc 5 - 2021-07-30 11:46:05.009,67,2002,2134567,CHARGEABLE
Doc 6 - 2021-07-30 11:46:17.133,46,2001,2134567,CHARGEABLE

```

**[Headers - Timestamp, Field\_Flag, Cause\_FLAG, TID, CHARGE\_FLAG]**

I want to make a KQL query to get count of TID's who's Field\_Flag = 67 and Cause\_FLAG = 2001 , And satisfies the condition -\> Field\_Flag = 46 and Cause\_Flag = 2001.

Here in this example, the count will be 1.

So the query is how to club these 2 different line condition to make a dashboard graph of such TID's counts?

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [August 1, 2021, 3:24pm UTC](https://discuss.elastic.co/t/complex-multi-line-condition-based-aggregation-kibana/280054/2 "2021-08-01T15:24:56Z")

</div>

> I want to make a KQL query to get count of TID's who's Field\_Flag = 67 and Cause\_FLAG = 2001 , And satisfies the condition -\> Field\_Flag = 46 and Cause\_Flag = 2001.

The "And" in "And satisfies the condition" would return no results as your data doesn't have a field\_flag with both 67 and 46. If you require either of these two cases to return a result (an 'or' instead of an 'and') then you do get your 1 result.

`(field_flag : 67 and cause_flag : 2001) or (field_flag : 46 and cause_flag : 2001)`

...which could also be written like:

`(field_flag : 67 or field_flag: 46) and (cause_flag : 2001)`

If you're counting TIDs, then don't forget to set up a unique count of that field in lens (or a "cardinality" aggregation in Elasticsearch) to return the unique count of those ID fields rather than a raw document count.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2021, 3:25pm UTC](https://discuss.elastic.co/t/complex-multi-line-condition-based-aggregation-kibana/280054/3 "2021-08-29T15:25:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
