# Filebeat+kibana+canvas

**URL:** <https://discuss.elastic.co/t/filebeat-kibana-canvas/211356>\
**Category:** Kibana\
**Created:** [December 10, 2019, 6:22pm UTC](https://discuss.elastic.co/t/filebeat-kibana-canvas/211356 "2019-12-10T18:22:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wadhah](https://avatars.discourse-cdn.com/v4/letter/w/bc8723/32.png) [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Post date:** [December 10, 2019, 6:22pm UTC](https://discuss.elastic.co/t/filebeat-kibana-canvas/211356/1 "2019-12-10T18:22:16Z")

</div>

Hello.  
I am new to filebeat and I am using it to inject logs into Elasticsearch.  
And, I want to build some visualizations in Kibana with the data that I am getting.  
Is it a good approach to go with Canvas, knowing that in my "filebeat\*" index i dispose of a field of type text and it has the shape of : {"a" : "expl\_1", "b" : "expl2" .....} and in my queries I need I need to use conditions based on that field:

SELECT c, d  
FROM "filebeat\*"  
WHERE a=expl\_1

or is there a better way to build the visualizations.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [December 16, 2019, 4:57pm UTC](https://discuss.elastic.co/t/filebeat-kibana-canvas/211356/2 "2019-12-16T16:57:38Z")

</div>

Hey @wadhah, there are a number of ways to visualize this data in Kibana. It really depends on what level of control you'd like over the query, and how much control you'd like over the output for which tool is best. Canvas allows you a lot of flexibility in regard to the way the data is rendered, but it can require a lot more effort to do so. If you're comfortable building this in Canvas, it allows you a lot of power.

---

<div class="post-metadata">

**Author:** ![wadhah](https://avatars.discourse-cdn.com/v4/letter/w/bc8723/32.png) [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Post date:** [December 16, 2019, 5:58pm UTC](https://discuss.elastic.co/t/filebeat-kibana-canvas/211356/3 "2019-12-16T17:58:12Z")

</div>

Thank you Brandon for your response.  
Like for example in the case that I have already established : let's assume In my index "filebeat-\*", I have 3 fields "field1", "field2" and "field3".  
"field3" is a text presented as follows : {"a" : "expl\_1", "b" : "expl2" .....}  
I want to count "field1" when "a" takes "expl1".

So, how does the query should look like?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2020, 5:58pm UTC](https://discuss.elastic.co/t/filebeat-kibana-canvas/211356/4 "2020-01-13T17:58:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
