# Complex query in Kibana

**URL:** <https://discuss.elastic.co/t/complex-query-in-kibana/62840>\
**Category:** Kibana\
**Created:** [October 12, 2016, 5:03pm UTC](https://discuss.elastic.co/t/complex-query-in-kibana/62840 "2016-10-12T17:03:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![quebecCu](https://avatars.discourse-cdn.com/v4/letter/q/f04885/32.png) [@quebecCu](https://discuss.elastic.co/u/quebecCu)\
**Post date:** [October 12, 2016, 5:03pm UTC](https://discuss.elastic.co/t/complex-query-in-kibana/62840/1 "2016-10-12T17:03:07Z")

</div>

Hello,

Is it possible to do a complex query in Kibana.

For example, i have tree rows:

```
{ip: 127.0.0.1, type: "type #1"}
{ip: 127.0.0.1, type: "type #2"}
{ip: 192.168.0.1, type: "type #1"}
{ip: 192.168.0.88, type: "type #2"}

```

Let say we want all the IPs who have the type : "type #1 AND type #2".  
The result would be two rows:

```
{ip: 127.0.0.1, type: "type #1"}
{ip: 127.0.0.1, type: "type #2"}

```

Is this possible in Kibana?

Thank you

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [October 12, 2016, 10:43pm UTC](https://discuss.elastic.co/t/complex-query-in-kibana/62840/2 "2016-10-12T22:43:59Z")

</div>

Hi there,

Yes it is possible to do a complex query. For your example, the query would look like this:

`type:"type #1" OR type:"type #2"`

For more info, check out these references:

- [https://www.elastic.co/guide/en/kibana/current/discover.html#search](https://www.elastic.co/guide/en/kibana/current/discover.html#search)
- [https://www.elastic.co/guide/en/elasticsearch/reference/current//query-dsl-query-string-query.html#query-string-syntax](https://www.elastic.co/guide/en/elasticsearch/reference/current//query-dsl-query-string-query.html#query-string-syntax)

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![quebecCu](https://avatars.discourse-cdn.com/v4/letter/q/f04885/32.png) [@quebecCu](https://discuss.elastic.co/u/quebecCu)\
**Post date:** [October 13, 2016, 1:17pm UTC](https://discuss.elastic.co/t/complex-query-in-kibana/62840/3 "2016-10-13T13:17:04Z")

</div>

Hello CJ,

thank you for the feedback!

However, I don't think this is the answer I am looking for.  
In this case, doing:  
`type:"type #1" OR type:"type #2"`  
will return me all fields described above, because all the fields described above are of Type 1 or 2.

What I want is a query based on the IP.  
The results would be all IP that are AND of type 1, AND of type 2, but would not include IPs that only have one type. I know we can do relations in elasticsearch, but I would like to know how to query those on Kibana.

Thank you,

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [October 17, 2016, 6:04pm UTC](https://discuss.elastic.co/t/complex-query-in-kibana/62840/4 "2016-10-17T18:04:06Z")

</div>

This is a bit complicated, but I think it's a clue to what you're trying to do. You could used the Advanced JSON Input field.

> [@Display concurrency in data on Kibana](https://discuss.elastic.co/t/display-concurrency-in-data-on-kibana/26006):
>
> I have fields with start date and duration (seconds) representing start and duration of a phone call. I would like to define concurrency (a number) when the same destination (also a field) is active within the same duration. That is if a ncall starts now for 30 seconds and another call to the same destination starts 15 seconds into the first call, concurrency should be 2 for the remaining 15 seconds. How do I define this in Kibana visualization as a line graph over time?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:36pm UTC](https://discuss.elastic.co/t/complex-query-in-kibana/62840/5 "2017-07-06T13:36:23Z")

</div>


