# Display all documents with duplicated value of a given field

**URL:** <https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246>\
**Category:** Kibana\
**Created:** [May 8, 2019, 8:12pm UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246 "2019-05-08T20:12:46Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![jcaballero](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@jcaballero](https://discuss.elastic.co/u/jcaballero)\
**Post date:** [May 8, 2019, 8:12pm UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/1 "2019-05-08T20:12:46Z")

</div>

Hi

Kibana 5.4.1

Let's say I have this type of data in ElasticSearch:

```
name <other fields>

aa ...
bb ...
cc ...
bb ...
dd ...
ee ...
ff ...
aa ...
gg ...

```

and so on.  
I would like to know if there is a way to use the query bar in Kibana, to display only those docs that have a common value of "name". Or, to say to opposite, filter those docs whose "name" is unique.  
The result would be like this:

```
name <other fields>

aa ...
bb ...
bb ...
aa ...

```

as 'aa' and 'bb' are the only values that show up more than once.  
Is this doable?

thanks a lot in advance.  
Cheers,  
Jose

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [May 8, 2019, 9:04pm UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/2 "2019-05-08T21:04:27Z")

</div>

hi @jcaballero,

the short answer there is _maybe_. It depends on what your limitations are.

You can create a data-table with a terms aggregation and set the `min_doc_count` parameter to 2.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#\_minimum\_document\_count\_4](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_minimum_document_count_4)

Then, run the terms aggregation on the `name` field.

To set the `min_doc_count` field, you'll need to set it using the advanced settings, and add it in the JSON-field.

e.g.: this will only return terms that have at least 100 matching documents

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d30291884779f40943c77412c37d54c8b90784ff.png)

---

<div class="post-metadata">

**Author:** ![jcaballero](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@jcaballero](https://discuss.elastic.co/u/jcaballero)\
**Post date:** [May 8, 2019, 9:11pm UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/3 "2019-05-08T21:11:42Z")

</div>

thanks @thomasneirynck for a so prompt response. I need to read carefully the documentation, as I never touched the advance settings, I don't want to break anything 🙂

---

<div class="post-metadata">

**Author:** ![jcaballero](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@jcaballero](https://discuss.elastic.co/u/jcaballero)\
**Post date:** [May 8, 2019, 10:07pm UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/4 "2019-05-08T22:07:28Z")

</div>

Hmm. Maybe there is an easier way, that does not requires playing with the delicate "advance settings"?  
One of the other fields in my docs happens to be a counter. So the data actually looks like this:

```
name counter <other fields>

aa 1 ...
bb 1 ...
cc 1 ...
bb 2 ...
dd 1 ...
ee 1 ...
ff 1 ...
aa 2 ...
gg 1 ...

```

and, therefore, the result of the query I am looking for would be like this:

```
name counter <other fields>

aa 1 ...
bb 1 ...
bb 2 ...
aa 2 ...

```

Is it possible to leverage somehow the existence of that counter thru the query bar?  
Something equivalent to (WARNING: pseudo-code) this?

```
SELECT * WHERE name = ( SELECT name WHERE counter > 1 )
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 8, 2019, 10:46pm UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/5 "2019-05-08T22:46:06Z")

</div>

You should just be able to add a filter for `counter > 1` then.

---

<div class="post-metadata">

**Author:** ![jcaballero](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@jcaballero](https://discuss.elastic.co/u/jcaballero)\
**Post date:** [May 9, 2019, 12:10am UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/6 "2019-05-09T00:10:02Z")

</div>

would then I see also "aa 1" and "bb 1"?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 9, 2019, 12:14am UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/7 "2019-05-09T00:14:16Z")

</div>

No because their counter values are greater than 1.

---

<div class="post-metadata">

**Author:** ![jcaballero](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@jcaballero](https://discuss.elastic.co/u/jcaballero)\
**Post date:** [May 9, 2019, 12:24am UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/8 "2019-05-09T00:24:07Z")

</div>

so it does not work as I need.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 9, 2019, 12:45am UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/9 "2019-05-09T00:45:47Z")

</div>

But aren't `aa 1` and `aa 2` the same?

---

<div class="post-metadata">

**Author:** ![jcaballero](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@jcaballero](https://discuss.elastic.co/u/jcaballero)\
**Post date:** [May 9, 2019, 12:54am UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/10 "2019-05-09T00:54:02Z")

</div>

Nope. Sorry I was not clear. Note that in my examples, I included "other fields". They are different. And that is what I want to see. All fields for all documents with a value for "name" (any value) that appears more than once.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2019, 12:54am UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246/11 "2019-06-06T00:54:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
