# Custom filter in kibana discover

**URL:** <https://discuss.elastic.co/t/custom-filter-in-kibana-discover/111927>\
**Category:** Kibana\
**Created:** [December 15, 2017, 8:58am UTC](https://discuss.elastic.co/t/custom-filter-in-kibana-discover/111927 "2017-12-15T08:58:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![blueren](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blueren](https://discuss.elastic.co/u/blueren)\
**Post date:** [December 15, 2017, 8:58am UTC](https://discuss.elastic.co/t/custom-filter-in-kibana-discover/111927/1 "2017-12-15T08:58:25Z")

</div>

Hello,

I'd like to know how I can set up a custom query in kibana's discover. My requirement is basically with respect to netflow data that is being stored in the elstic db. I'd like to query:

Show all netflow records where either client\_addr is between (...) **OR** server\_addr is between (...)

Adding multiple filters, one for client\_addr and one for server\_addr in fact seems to do an AND operation. How do I go about having an OR operation?

Thanks.

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [December 15, 2017, 9:16am UTC](https://discuss.elastic.co/t/custom-filter-in-kibana-discover/111927/2 "2017-12-15T09:16:02Z")

</div>

Hi,

you can use the "Edit Query DSL" when creating a filter to freely type in any Elasticsearch Query DSL query to use. For an _OR_ query Elasticsearch uses [Bool queries](https://www.elastic.co/guide/en/elasticsearch/reference/6.x/query-dsl-bool-query.html) with a `should` key and a `minimum_should_match` value. Your desired query looks like:

```json
{
  "bool": {
    "should": [
      {
        "range": {
          "client_addr": {
            "gte": "0.0.0.0",
            "lt": "100.0.0.0"
          }
        }
      },
      {
        "range": {
          "server_addr": {
            "gte": "0.0.0.0",
            "lt": "100.0.0.0"
          }
        }
      }
    ],
    "minimum_should_match": 1
  }
}

```

The `minimum_should_match` states, that at least 1 entry from your `should` list must match the document.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![blueren](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blueren](https://discuss.elastic.co/u/blueren)\
**Post date:** [December 15, 2017, 9:29am UTC](https://discuss.elastic.co/t/custom-filter-in-kibana-discover/111927/4 "2017-12-15T09:29:00Z")

</div>

Thanks for the quick turnaround Tim, however, I seem to be hitting this error. Is it something to do with the syntax?

```
{
  "error": {
    "root_cause": [
      {
        "type": "parsing_exception",
        "reason": "Unknown key for a START_OBJECT in [bool].",
        "line": 2,
        "col": 11
      }
    ],
    "type": "parsing_exception",
    "reason": "Unknown key for a START_OBJECT in [bool].",
    "line": 2,
    "col": 11
  },
  "status": 400
}
```

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [December 15, 2017, 9:32am UTC](https://discuss.elastic.co/t/custom-filter-in-kibana-discover/111927/5 "2017-12-15T09:32:48Z")

</div>

It might be, depending on your version, that you need to nest the query in another `query` object:

```json
{
  "query": {
    "bool": {
      "should": [
        {
          "range": {
            "client_addr": {
              "gte": "0.0.0.0",
              "lt": "100.0.0.0"
            }
          }
        },
        {
          "range": {
            "server_addr": {
              "gte": "0.0.0.0",
              "lt": "100.0.0.0"
            }
          }
        }
      ],
      "minimum_should_match": 1
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![blueren](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blueren](https://discuss.elastic.co/u/blueren)\
**Post date:** [December 18, 2017, 5:30am UTC](https://discuss.elastic.co/t/custom-filter-in-kibana-discover/111927/6 "2017-12-18T05:30:24Z")

</div>

Thanks Tim. This worked perfectly!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2018, 5:30am UTC](https://discuss.elastic.co/t/custom-filter-in-kibana-discover/111927/7 "2018-01-15T05:30:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
