# Count with condition

**URL:** <https://discuss.elastic.co/t/count-with-condition/179976>\
**Category:** Kibana\
**Created:** [May 7, 2019, 12:48pm UTC](https://discuss.elastic.co/t/count-with-condition/179976 "2019-05-07T12:48:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shawcs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shawcs/32/45490_2.png) [@Shawcs](https://discuss.elastic.co/u/Shawcs)\
**Post date:** [May 7, 2019, 12:48pm UTC](https://discuss.elastic.co/t/count-with-condition/179976/1 "2019-05-07T12:48:01Z")

</div>

Hi,

i'm new to kibana and I'm struggling with the query. Here is what I want to archieve:

I have log for stransaction, this transaction is splited in 2 different log. One containing information about the transaction final status and one with the information about other internal status.  
My goal is to count the number of transaction that failed where the internal status is not fail.

Example of a log imput as my explanation can be vague.

Transaction:

```
{
"id":"1234",
"final status":"success"
}

```

global Transaction:

```
{
"id":"1234",
"internal status":"failed"
}

```

In this case my count would be 1

Any advice ?

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [May 7, 2019, 10:25pm UTC](https://discuss.elastic.co/t/count-with-condition/179976/2 "2019-05-07T22:25:31Z")

</div>

Hi @Shawcs,

> the number of transaction that failed where the internal status is not fail.

I'm not sure I'm following... are you saying that you want to find IDs where `final status: failed` but `internal status: not failed`?

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [May 7, 2019, 10:26pm UTC](https://discuss.elastic.co/t/count-with-condition/179976/3 "2019-05-07T22:26:07Z")

</div>

Or (re-reading your question) are you simply looking for documents where the `internal status` field equals `failed`?

---

<div class="post-metadata">

**Author:** ![Shawcs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shawcs/32/45490_2.png) [@Shawcs](https://discuss.elastic.co/u/Shawcs)\
**Post date:** [May 13, 2019, 7:45am UTC](https://discuss.elastic.co/t/count-with-condition/179976/4 "2019-05-13T07:45:54Z")

</div>

Hi @lukeelmers.

My count condition would be the following:

If log entry have the same ID, and we have for this id a final status as success and an internal status as failed we have a count +1

So regarding your answer yes it's your first response

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2019, 7:45am UTC](https://discuss.elastic.co/t/count-with-condition/179976/5 "2019-06-10T07:45:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
