# Filter records with a change in a particular field during a period

**URL:** <https://discuss.elastic.co/t/filter-records-with-a-change-in-a-particular-field-during-a-period/275018>\
**Category:** Kibana\
**Created:** [June 5, 2021, 9:18am UTC](https://discuss.elastic.co/t/filter-records-with-a-change-in-a-particular-field-during-a-period/275018 "2021-06-05T09:18:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eugene\_Korepanov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eugene_korepanov/32/78288_2.png) [@Eugene\_Korepanov](https://discuss.elastic.co/u/Eugene_Korepanov)\
**Post date:** [June 5, 2021, 9:18am UTC](https://discuss.elastic.co/t/filter-records-with-a-change-in-a-particular-field-during-a-period/275018/1 "2021-06-05T09:18:12Z")

</div>

I have multiple hosts reporting some fields every day. I need to find sources that got a change in a value of a particular field. Let's say yesterday "field1" was 0 and today 1.  
In addition to that, I need to build a table of all the filtered sources together with some more fields that can help to understand why "field1" was changed:  
Source|Field1|Field2|Field3|  
where source in a list of those that changed field between day 1 and day 2.

Can you suggest a suitable tool in kibana? I couldn't find one myself ☹

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [June 7, 2021, 12:52pm UTC](https://discuss.elastic.co/t/filter-records-with-a-change-in-a-particular-field-during-a-period/275018/2 "2021-06-07T12:52:33Z")

</div>

try filtering for this value of field1 in Discover and include the fields you need in the table. also, if you have it licensed, it also seems like you are describing machine learning features like anomaly detection

---

<div class="post-metadata">

**Author:** ![Eugene\_Korepanov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eugene_korepanov/32/78288_2.png) [@Eugene\_Korepanov](https://discuss.elastic.co/u/Eugene_Korepanov)\
**Post date:** [June 8, 2021, 3:51am UTC](https://discuss.elastic.co/t/filter-records-with-a-change-in-a-particular-field-during-a-period/275018/3 "2021-06-08T03:51:34Z")

</div>

Hi Graham, thanks for the reply, but my biggest problem is to find those sources that changed the field1 value. And the field is not binary. So it could be 1-\>2, or 4-\>3, or god knows what...

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 8, 2021, 10:41am UTC](https://discuss.elastic.co/t/filter-records-with-a-change-in-a-particular-field-during-a-period/275018/4 "2021-06-08T10:41:37Z")

</div>

Yes, seems like Anomaly Detection would be worth considering for this use case

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2021, 10:42am UTC](https://discuss.elastic.co/t/filter-records-with-a-change-in-a-particular-field-during-a-period/275018/5 "2021-07-06T10:42:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
