# ELK Kibana table grouping count

**URL:** <https://discuss.elastic.co/t/elk-kibana-table-grouping-count/259422>\
**Category:** Kibana\
**Created:** [December 22, 2020, 7:03pm UTC](https://discuss.elastic.co/t/elk-kibana-table-grouping-count/259422 "2020-12-22T19:03:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Atif\_EL\_KHACHINE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/atif_el_khachine/32/81273_2.png) [@Atif\_EL\_KHACHINE](https://discuss.elastic.co/u/Atif_EL_KHACHINE)\
**Post date:** [December 22, 2020, 7:03pm UTC](https://discuss.elastic.co/t/elk-kibana-table-grouping-count/259422/1 "2020-12-22T19:03:03Z")

</div>

Hi,  
I have some data :

`{"groupname":"ZAAH", "dname":"DEVICE1", "status":"OK"}`

`{"groupname":"ZAAH","dname":"DEVICE2", "status":"ERROR"}`

`{"groupname":"ZAAH","dname":"DEVICE3", "status":"OK"}`  
`{"groupname":"ZAAH","dname":"DEVICE3", "status":"ERROR"}`

`{"groupname":"ZAAH","dname":"DEVICE4", "status":"ERROR"}`  
`{"groupname":"ZAAH","dname":"DEVICE4", "status":"OK"}`

How can i do with lets say Kibana table to get this result (status OK is higher than ERROR, so if a device send 2 status OK and ERROR / or ERROR and OK, we consider the device is OK) :

`groupname status count`  
`ZAAH OK 3 (because device1 is OK + device3 is OK + device4 is OK)`  
`ZAAH ERROR 1 (because device2 is ERROR)`

Any hints are welcome.

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [December 22, 2020, 9:46pm UTC](https://discuss.elastic.co/t/elk-kibana-table-grouping-count/259422/2 "2020-12-22T21:46:37Z")

</div>

Hi, welcome! Not all of the parts of your question are directly supported by Kibana. Kibana is able to show you a table based on the Terms aggregation, so you could for example show the count for each (groupname, dname, status) tuple in alphabetical order- but without extra processing. Would that work?

If that doesn't work, then I think you have two options:

1. Change the data format, for example by [using the Transform API](https://www.elastic.co/guide/en/elasticsearch/reference/current/transforms.html) which is often used in this type of data
2. Switch to a different visualization type, specifically [Vega](https://www.elastic.co/guide/en/kibana/current/vega-lite-tutorial-create-your-first-visualizations.html), which is more powerful- but doesn't do great tables

---

<div class="post-metadata">

**Author:** ![Atif\_EL\_KHACHINE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/atif_el_khachine/32/81273_2.png) [@Atif\_EL\_KHACHINE](https://discuss.elastic.co/u/Atif_EL_KHACHINE)\
**Post date:** [December 24, 2020, 10:56am UTC](https://discuss.elastic.co/t/elk-kibana-table-grouping-count/259422/3 "2020-12-24T10:56:02Z")

</div>

Hi, thank you for your feedback. I have never used Vega or tansform api. Do you know how can i accomplish the task with Vega ? or easier with Transform api ?

Thank you again

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [December 28, 2020, 4:28pm UTC](https://discuss.elastic.co/t/elk-kibana-table-grouping-count/259422/4 "2020-12-28T16:28:42Z")

</div>

Both options I recommended will require some work to set up correctly- if you _require_ a table, then you can't use Vega. My personal preference is Vega: it's very powerful once you learn it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 25, 2021, 4:28pm UTC](https://discuss.elastic.co/t/elk-kibana-table-grouping-count/259422/5 "2021-01-25T16:28:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
