# Create Pie graph with filter

**URL:** <https://discuss.elastic.co/t/create-pie-graph-with-filter/174430>\
**Category:** Kibana\
**Created:** [March 28, 2019, 8:59pm UTC](https://discuss.elastic.co/t/create-pie-graph-with-filter/174430 "2019-03-28T20:59:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![xefil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xefil/32/43040_2.png) [@xefil](https://discuss.elastic.co/u/xefil)\
**Post date:** [March 28, 2019, 8:59pm UTC](https://discuss.elastic.co/t/create-pie-graph-with-filter/174430/1 "2019-03-28T20:59:39Z")

</div>

Hi all,  
I'm new to this product and it's amazing!  
BTW I've a lot to learn and I'm already having issues with a simple graph.  
I'm logging pfSense logs (firewall). I would like to create i.e. a pie graph that shows me blocked rules against passed rules. Until here ok:  
Pie graph with metric count, Split slice, aggreations: Terms, Field: action.keyword, Metric: Count.  
This gives me a nice pie showing me PASS / BLOCK count.  
BUT how to implement that it should NOT count in example records that contains Fields dest\_ip.keyword = "192.168.1.1" ?  
I cannot use the "Exclude" of JSON Input.  
Thanks a lot!  
Simon

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [March 29, 2019, 9:14pm UTC](https://discuss.elastic.co/t/create-pie-graph-with-filter/174430/2 "2019-03-29T21:14:50Z")

</div>

> [@xefil](#):
>
> BUT how to implement that it should NOT count in example records that contains Fields dest\_ip.keyword = "192.168.1.1" ?

Hi, one way to do this would be to first filter the underlying data using a saved search for the visualization.

- From Discover, click "New", and pick your index pattern and time range.
- Click "Add a filter" and use the controls to make a `NOT dest_ip.keyword: "192.168.1.1"` filter
- Save the search and name it something meaningful, like `logs-filtered`
- Make a new Pie Chart visualization. After picking the type of visualization, you're presented with a screen titled, "Choose a search source". Instead of selecting the "index" as before, select the `logs-filtered` search

What's great about this is you can link many visualizations to the same search, and you can change the search after visualizations are linked to improve the filters.

BTW I'm using Kibana 6.7.0. The titles of the screens and steps may be different for me.

---

<div class="post-metadata">

**Author:** ![xefil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xefil/32/43040_2.png) [@xefil](https://discuss.elastic.co/u/xefil)\
**Post date:** [March 31, 2019, 2:37pm UTC](https://discuss.elastic.co/t/create-pie-graph-with-filter/174430/3 "2019-03-31T14:37:47Z")

</div>

Hello!  
Thanks a lot for the suggestions! I'll give it a try, and yes, I've not understood previosly that I can simply apply a filter on the search itself and the graph is then updated 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2019, 2:37pm UTC](https://discuss.elastic.co/t/create-pie-graph-with-filter/174430/4 "2019-04-28T14:37:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
