# Exclude records by an existing value in a group

**URL:** <https://discuss.elastic.co/t/exclude-records-by-an-existing-value-in-a-group/217849>\
**Category:** Kibana\
**Created:** [February 4, 2020, 4:25pm UTC](https://discuss.elastic.co/t/exclude-records-by-an-existing-value-in-a-group/217849 "2020-02-04T16:25:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Carlos\_Arturo\_Bernal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_arturo_bernal/32/46269_2.png) [@Carlos\_Arturo\_Bernal](https://discuss.elastic.co/u/Carlos_Arturo_Bernal)\
**Post date:** [February 4, 2020, 4:25pm UTC](https://discuss.elastic.co/t/exclude-records-by-an-existing-value-in-a-group/217849/1 "2020-02-04T16:25:29Z")

</div>

Hello,

I'm currently storing in ElasticSearch build data from Jenkins, related to the success of client deployments. If we see such data as a table, this is what I have:

| client\_id | build\_url | result |
| --- | --- | --- |
| 123456 | [http://jenkins.com/build/1](http://jenkins.com/build/1) | FAILURE |
| 123456 | [http://jenkins.com/build/2](http://jenkins.com/build/2) | FAILURE |
| 123456 | [http://jenkins.com/build/3](http://jenkins.com/build/3) | SUCCESS |
| 789999 | [http://jenkins.com/build/4](http://jenkins.com/build/4) | FAILURE |
| 789999 | [http://jenkins.com/build/5](http://jenkins.com/build/5) | SUCCESS |
| 258963 | [http://jenkins.com/build/6](http://jenkins.com/build/6) | FAILURE |
| 258963 | [http://jenkins.com/build/7](http://jenkins.com/build/7) | FAILURE |
| 458963 | [http://jenkins.com/build/8](http://jenkins.com/build/8) | FAILURE |

I want to create a table visualization in Kibana that shows all the failed builds for clients that **didn't had at least one SUCCESS**.

So, for the example data set above, I would expect to only see:

| client\_id | build\_url | result |
| --- | --- | --- |
| 258963 | [http://jenkins.com/build/6](http://jenkins.com/build/6) | FAILURE |
| 258963 | [http://jenkins.com/build/7](http://jenkins.com/build/7) | FAILURE |
| 458963 | [http://jenkins.com/build/8](http://jenkins.com/build/8) | FAILURE |

Does anyone know how I could create this sort of group filtering? I would need this by `client_id`.

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [February 4, 2020, 9:29pm UTC](https://discuss.elastic.co/t/exclude-records-by-an-existing-value-in-a-group/217849/2 "2020-02-04T21:29:26Z")

</div>

Hi @Carlos_Arturo_Bernal. Sorry, I don't know of any great ways to do this. The closest I came was with a Top Hit aggregation in TSVB.

 ![Screenshot_2020-02-04 Jenkins failures - Kibana](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c103573d8335dec2518da43f1d9a5c032babb88.png)

---

<div class="post-metadata">

**Author:** ![Carlos\_Arturo\_Bernal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_arturo_bernal/32/46269_2.png) [@Carlos\_Arturo\_Bernal](https://discuss.elastic.co/u/Carlos_Arturo_Bernal)\
**Post date:** [February 4, 2020, 10:45pm UTC](https://discuss.elastic.co/t/exclude-records-by-an-existing-value-in-a-group/217849/3 "2020-02-04T22:45:04Z")

</div>

@nickpeihl even thought it's not the table that I expected, it could just be good enough for my current needs.

Thanks a lot!

FYI: I was able do the same thing in the table visualization (no TSVB).

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [February 4, 2020, 11:04pm UTC](https://discuss.elastic.co/t/exclude-records-by-an-existing-value-in-a-group/217849/4 "2020-02-04T23:04:42Z")

</div>

Hi @Carlos_Arturo_Bernal. I believe Kibana would need to support the bucket selector pipeline aggregation to accomplish the filtering. Feel free to add your use case and express your need for this in this issue. [https://github.com/elastic/kibana/issues/17544](https://github.com/elastic/kibana/issues/17544)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2020, 11:04pm UTC](https://discuss.elastic.co/t/exclude-records-by-an-existing-value-in-a-group/217849/5 "2020-03-03T23:04:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
