# Datatable - two counts with different filters

**URL:** <https://discuss.elastic.co/t/datatable-two-counts-with-different-filters/140337>\
**Category:** Kibana\
**Created:** [July 17, 2018, 1:39pm UTC](https://discuss.elastic.co/t/datatable-two-counts-with-different-filters/140337 "2018-07-17T13:39:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tallavi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tallavi/32/73613_2.png) [@tallavi](https://discuss.elastic.co/u/tallavi)\
**Post date:** [July 17, 2018, 1:39pm UTC](https://discuss.elastic.co/t/datatable-two-counts-with-different-filters/140337/1 "2018-07-17T13:39:51Z")

</div>

Hi,

Let's say I have these documents:

service1 INFO "log line 1"  
service1 INFO "log line 2"  
service1 ERROR "error 1"  
service2 INFO "log line 1"

I know how to make a table with total counts:

service count  
service1 3  
service2 1

I know how to make a table with just errors count:

service count  
service1 1

BUT, can I make a single table somehow? Different filters for each count??

service total\_count errors\_count  
service1 3 1  
service2 1 -

Thanks!

Tal

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [July 17, 2018, 10:05pm UTC](https://discuss.elastic.co/t/datatable-two-counts-with-different-filters/140337/2 "2018-07-17T22:05:52Z")

</div>

Hi there, sorry but you can't do exactly what you're asking for. Could you file a feature request on the [GitHub repo](https://github.com/elastic/kibana/issues)?

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [July 17, 2018, 10:31pm UTC](https://discuss.elastic.co/t/datatable-two-counts-with-different-filters/140337/3 "2018-07-17T22:31:44Z")

</div>

Actually after some digging I think I may have a solution for you. In the screenshot below, substitute the `geo.src` field for your `service` field and the `machine.os:ios` filter for `status:ERROR` (or something similar to filter on the error field). The second filter is blank, which will give you rows with total counts next to rows with error counts.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/3/4381ac015bf2ca8ca1bdd78dc0b4a68ebaad6183.png)

---

<div class="post-metadata">

**Author:** ![tallavi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tallavi/32/73613_2.png) [@tallavi](https://discuss.elastic.co/u/tallavi)\
**Post date:** [July 19, 2018, 5:06pm UTC](https://discuss.elastic.co/t/datatable-two-counts-with-different-filters/140337/4 "2018-07-19T17:06:26Z")

</div>

> [@cjcenizal](#):
>
> Actually after some digging I think I may have a solution for you.

Thanks for the workaround! It's not as elegant as having the errors and total be in a single row, but it's something.

I will open a feature request on github. I think that what we need is to have a filter on the metrics, then I can add different filters for two count metrics.

Thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2018, 5:06pm UTC](https://discuss.elastic.co/t/datatable-two-counts-with-different-filters/140337/5 "2018-08-16T17:06:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
