# Few Questions related to capability of Kibana?

**URL:** <https://discuss.elastic.co/t/few-questions-related-to-capability-of-kibana/186813>\
**Category:** Kibana\
**Created:** [June 21, 2019, 7:12am UTC](https://discuss.elastic.co/t/few-questions-related-to-capability-of-kibana/186813 "2019-06-21T07:12:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shankarananth](https://avatars.discourse-cdn.com/v4/letter/s/4da419/32.png) [@shankarananth](https://discuss.elastic.co/u/shankarananth)\
**Post date:** [June 21, 2019, 7:12am UTC](https://discuss.elastic.co/t/few-questions-related-to-capability-of-kibana/186813/1 "2019-06-21T07:12:54Z")

</div>

Hai All,

I'm newbie to ELK. I do have previous working exp with splunk..  
I have 4 questions over here. Sorry, may be my questions some are very basic.  
If you answer for below question it will be very helpful for me ..

1. When data is already available in Elasticsearch. Eg (Message= 678990.R\_Data\_Lon\_960\_008.IN).  
Is it possible to extract or split the above Message field and store them as separate field using Kibana Eg (Token=678990, Rate=R,File=Data,Location=Lon,Runid=960,Check=008,Progress=IN).

2. We have a concept called lookup in Splunk. External file can be inserted into splunk and with the help of common field between index and lookup file. We can fetch the data from lookup file and display in the dashboard. Do we have similar functionality in kibana.

3. Do we have join functionality in Kibana. If not do we have alternate way to achieve the same functionality using Kibana.

4. Can we able to setup the static value in dropdown filter of kibana?

Thanks in advance..

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 21, 2019, 8:30am UTC](https://discuss.elastic.co/t/few-questions-related-to-capability-of-kibana/186813/2 "2019-06-21T08:30:06Z")

</div>

> [@shankarananth](#):
>
> When data is already available in Elasticsearch. Eg (Message= 678990.R\_Data\_Lon\_960\_008.IN).  
> Is it possible to extract or split the above Message field and store them as separate field using Kibana Eg (Token=678990, Rate=R,File=Data,Location=Lon,Runid=960,Check=008,Progress=IN).

When working with the Elasticstack this is done before you index data into Elasticsearch, which is one of the main differences compared to Splunk. See [this blog post](https://www.elastic.co/blog/schema-on-write-vs-schema-on-read) for further details.

> [@shankarananth](#):
>
> We have a concept called lookup in Splunk. External file can be inserted into splunk and with the help of common field between index and lookup file. We can fetch the data from lookup file and display in the dashboard. Do we have similar functionality in kibana.

No, not what I am aware of. This kind of enrichment is typically also done at indexing time.

> [@shankarananth](#):
>
> Do we have join functionality in Kibana. If not do we have alternate way to achieve the same functionality using Kibana.

Elasticsearch and Kibana does not support joins. There are different types of workarounds that depend on the exact scenario, some of which are (again) performed at index time.

> [@shankarananth](#):
>
> Can we able to setup the static value in dropdown filter of kibana?

Am not sure so will leave that for someone else.

---

<div class="post-metadata">

**Author:** ![martinr\_ubi](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Post date:** [June 21, 2019, 9:46am UTC](https://discuss.elastic.co/t/few-questions-related-to-capability-of-kibana/186813/3 "2019-06-21T09:46:21Z")

</div>

> We have a concept called lookup in Splunk. External file can be inserted into splunk and with the help of common field between index and lookup file. We can fetch the data from lookup file and display in the dashboard. Do we have similar functionality in kibana.

I think it's fair to say there is _limited_ support for this in Kibana, it's called Static Lookup, see the screenshot:

 ![kibana_static_lookup](https://us1.discourse-cdn.com/elastic/original/3X/2/2/2243934151a9d591896f9e3ba18e1246e1f54553.png)

But yeah you'll be _disappointed_ if you start comparing this with Splunk Lookups. ES wants you to put that looked up(resolved) value IN the document being indexed to save time at query time and NOT have to make a lookup.

Splunk spends cycles at search time, ES spends cycles at indexing/pre-indexing times. The blog post referenced above will explain what we mean by this. The opinion of the platform is totally reverse when comparing Splunk and ES. (I run massive installs of both.)

In ES+logstash you do this by inserting the looked up value in the document(event) itself. Logstash has features for this and can look it up/cache it, etc. ES itself though ingest pipelines could do the same but in a way you could find awkward or certainly less dynamic at first. An ingest pipeline can contain the lookup table and do the job. It depends if the lookup table is fixed enough to "live" in the ingest pipeline itself.

> Can we able to setup the static value in dropdown filter of kibana?

The way this works in Kibana, it would make no sense. In short the dropdown is built with all the possible values found in a field and when you select an entry it filters that very same field for the value(s) you selected.  
[https://www.elastic.co/guide/en/kibana/current/add-input-controls.html](https://www.elastic.co/guide/en/kibana/current/add-input-controls.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2019, 9:46am UTC](https://discuss.elastic.co/t/few-questions-related-to-capability-of-kibana/186813/4 "2019-07-19T09:46:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
