# Data Table multiple event IDs

**URL:** <https://discuss.elastic.co/t/data-table-multiple-event-ids/109971>\
**Category:** Kibana\
**Created:** [December 1, 2017, 6:32pm UTC](https://discuss.elastic.co/t/data-table-multiple-event-ids/109971 "2017-12-01T18:32:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 1, 2017, 6:32pm UTC](https://discuss.elastic.co/t/data-table-multiple-event-ids/109971/1 "2017-12-01T18:32:23Z")

</div>

Trying to build a data table with split rows from multiple windows event ID's.

Event ID 4648 - Network Logon with exp credentials  
Grabbing the following-  
Computer\_Name TargetUsername SubjectUsername TargetServer

works great. But I want to have a table with several different event ID's that may or may not have that field

Event ID 4624 - NTLM Authentication  
Computer\_Name TargetUsername SubjectUsername ... but not TargetServer

so you can't see both event ID's on the same data table.

Is there a way to still show the data table even if the event ID's don't have the same exact fields? I.E. if the event ID isn't present just show the field as blank?

So I could show both 4648 and 4624 in the same table on the same visualization with similar but not perfect matching fields?

Thanks!

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [December 1, 2017, 11:35pm UTC](https://discuss.elastic.co/t/data-table-multiple-event-ids/109971/2 "2017-12-01T23:35:01Z")

</div>

Hi Matt,

Are you aggregating anything in this data table? If not, you can show these columns regardless of each doc having that field in the Discover table.  
But I'm guessing you're getting some count of each of these IDs or something? Or the list of unique IDs?

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 2, 2017, 4:51am UTC](https://discuss.elastic.co/t/data-table-multiple-event-ids/109971/3 "2017-12-02T04:51:38Z")

</div>

Hey Lee,

I am splitting the rows like this ...  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/6/467d62d6444f7ade8faa6c6a8fb5be41ffa54c9d.png)

... the end goal of this is to show if/then logic behind the scenes... if event 4648 AND event 4697 happen for the same computer\_name withing @timestamp 5 minutes of each other display these in the table.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [December 4, 2017, 3:30am UTC](https://discuss.elastic.co/t/data-table-multiple-event-ids/109971/4 "2017-12-04T03:30:37Z")

</div>

I'm thinking that's going to be pretty hard to do in Kibana (if it's even possible at all). I expected you would have to use the Advanced JSON Input field. Here's one example;

> [@Display concurrency in data on Kibana](https://discuss.elastic.co/t/display-concurrency-in-data-on-kibana/26006/4):
>
> Wow, nice script @colings86 and @jpountz@EricK if you have scripting enabled in elasticsearch you can use it within your date\_histogram by overriding the aggregations parameters with the "JSON input" advanced config option. This would look something like the screenshot below (note the field: null bit which removes the field parameter from the params):

You might need to post a question in the Elasticsearch channel to ask how to write the appropriate query and then come back to Kibana and try to create the visualization .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 1, 2018, 3:30am UTC](https://discuss.elastic.co/t/data-table-multiple-event-ids/109971/5 "2018-01-01T03:30:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
