# Executing terms filter search on an index in Kibana

**URL:** <https://discuss.elastic.co/t/executing-terms-filter-search-on-an-index-in-kibana/42110>\
**Category:** Kibana\
**Created:** [February 18, 2016, 8:29am UTC](https://discuss.elastic.co/t/executing-terms-filter-search-on-an-index-in-kibana/42110 "2016-02-18T08:29:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Natarajan\_venkataram](https://avatars.discourse-cdn.com/v4/letter/n/f14d63/32.png) [@Natarajan\_venkataram](https://discuss.elastic.co/u/Natarajan_venkataram)\
**Post date:** [February 18, 2016, 8:29am UTC](https://discuss.elastic.co/t/executing-terms-filter-search-on-an-index-in-kibana/42110/1 "2016-02-18T08:29:21Z")

</div>

I want to filter execute terms filter search on my dashboard, but however I'm seeing no results, even though I could see that there is a match, and the string fields are indexed as not\_analyzed, as suggested for terms filter search.

Details :  
I have 2 indices - A & B.

Index A has the device logs which contains the list of IPs that were connected among other fields.  
Index B has list of blacklisted IPs and their details.

I want to check if any of the blacklist IPs( in index B) are present in IP list in Index A.

Can you please let me know how to do this in Kibana.

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [February 18, 2016, 1:44pm UTC](https://discuss.elastic.co/t/executing-terms-filter-search-on-an-index-in-kibana/42110/2 "2016-02-18T13:44:38Z")

</div>

I don't believe this type of visual join is easily possible in Kibana (or Elasticsearch for that matter) out of the box. See an old discussion from Kibana 3 days about it: [https://github.com/elastic/kibana/issues/1012](https://github.com/elastic/kibana/issues/1012)

You may need a custom client/UI to do that that accomplishes the join outside Kibana. I'm aware of 3rd party tools that try to add relational semantics on top of Elasticsearch, so that may be an option as well: [https://siren.solutions/kibi/](https://siren.solutions/kibi/)

---

<div class="post-metadata">

**Author:** ![stormpython](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stormpython/32/7190_2.png) [@stormpython](https://discuss.elastic.co/u/stormpython)\
**Post date:** [February 18, 2016, 5:46pm UTC](https://discuss.elastic.co/t/executing-terms-filter-search-on-an-index-in-kibana/42110/3 "2016-02-18T17:46:07Z")

</div>

Natarajan,

There might be a hacky workaround to what you want to do. It's not pretty, but should work.

If in index A and index B, you have a field for `clientip` which shares the same name. Then you could create a table visualization of the top N ips in index B (blacklist index) and a top N ips table for index A and place both on the dashboard. Then in the search box at the top, you could filter for ips from the blacklisted table (index B) and see if those ips show up in the other table (index A). But it would require that the field name for ips remain the same across indices.

---

<div class="post-metadata">

**Author:** ![Natarajan\_venkataram](https://avatars.discourse-cdn.com/v4/letter/n/f14d63/32.png) [@Natarajan\_venkataram](https://discuss.elastic.co/u/Natarajan_venkataram)\
**Post date:** [February 21, 2016, 5:48am UTC](https://discuss.elastic.co/t/executing-terms-filter-search-on-an-index-in-kibana/42110/4 "2016-02-21T05:48:13Z")

</div>

Yep, I was following this method till now. But, it did'nt solve my problem. The count of blacklisted IPs are in 1000s and getting updated regulary. Hence the suggested method may not work out.

---

<div class="post-metadata">

**Author:** ![Natarajan\_venkataram](https://avatars.discourse-cdn.com/v4/letter/n/f14d63/32.png) [@Natarajan\_venkataram](https://discuss.elastic.co/u/Natarajan_venkataram)\
**Post date:** [February 21, 2016, 10:49am UTC](https://discuss.elastic.co/t/executing-terms-filter-search-on-an-index-in-kibana/42110/5 "2016-02-21T10:49:18Z")

</div>

Thanks @tbragin . The Siren Kibi solves my problem, and they also support the latest version elasticsearch.

Are there any plans in pipeline to support those kind of features in Kibana ? I understand that this will require elasticsearch to support relational data models natively.

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [February 21, 2016, 2:29pm UTC](https://discuss.elastic.co/t/executing-terms-filter-search-on-an-index-in-kibana/42110/6 "2016-02-21T14:29:37Z")

</div>

> [@Natarajan\_venkataram](#):
>
> Are there any plans in pipeline to support those kind of features in Kibana ? I understand that this will require elasticsearch to support relational data models natively.

There are no such plans at this time, as it's hard to do just in the UI in a way that scales well to large data sets. We will continue to think about it though!

Note that stormpython had a good suggestion above for a way to make this work in Kibana, if IP field names match across indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:01pm UTC](https://discuss.elastic.co/t/executing-terms-filter-search-on-an-index-in-kibana/42110/7 "2017-07-06T14:01:29Z")

</div>


