# Filtering for multiple values in a single field

**URL:** <https://discuss.elastic.co/t/filtering-for-multiple-values-in-a-single-field/224627>\
**Category:** Kibana\
**Created:** [March 23, 2020, 9:01am UTC](https://discuss.elastic.co/t/filtering-for-multiple-values-in-a-single-field/224627 "2020-03-23T09:01:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jakobtahe](https://avatars.discourse-cdn.com/v4/letter/j/f475e1/32.png) [@jakobtahe](https://discuss.elastic.co/u/jakobtahe)\
**Post date:** [March 23, 2020, 9:01am UTC](https://discuss.elastic.co/t/filtering-for-multiple-values-in-a-single-field/224627/1 "2020-03-23T09:01:08Z")

</div>

Hi all,

I have a data set with among others the following fields: `Customer_name`, `Product_name` and `Price` and all sales are entered into Kibana as a single document.

Since my user group is a group of non coding users, I've created a dashboard and want to enable the users to find Customers that has purchased a combination of products. E.g. I want the user to be able to select Product A AND Product B AND Product C and see which customer that has purchased ALL of these products.

When I write `Product_name` : (Product A AND Product B) in the Filter bar I get no results. However if I write the filter as `Product_name` : Product A OR Product B I get the result of all customers that has EITHER bought Product A OR Product B but I'm only interested in the ones that has bought them BOTH.

Is there anyway to search for multiple results from a single field in the Kibana UI and writing a query to get the result?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0ef94d3cad72f94db055323a44a42db1f1325083.png)

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [March 23, 2020, 5:10pm UTC](https://discuss.elastic.co/t/filtering-for-multiple-values-in-a-single-field/224627/2 "2020-03-23T17:10:51Z")

</div>

A filter is always applied on the document level - as `Product_name` is just a single product per document, you can't match multiple at once.

When modeling your data, it's always important to think about what entity one document is - in your case I assume it's a sale - one product sold to one customer (on multiple occasions). Based on your description it sounds like the users want to search customer-centric instead, so each document in your data set should represent a customer. Maybe you even want to do both things depending on the scenario.

Consider shaping your data differently and providing it in the form you need

So instead of having an index `sales` with

```auto
{
  customer: A,
  product: B,
  price: 123
}
{
  customer: A,
  product: C,
  price: 456
}

```

add an index `customers` with

```auto
{
  customer: A,
  products: [B, C],
  price: [123, 456]
}

```

On the second index you can search for `products : (Product A AND Product B) ` and it will give you what you are looking for.

In some cases this might not be what you want and the `sales` view is the right one - in that case duplicating the data and keeping around both indices is probably a good approach.

---

<div class="post-metadata">

**Author:** ![jakobtahe](https://avatars.discourse-cdn.com/v4/letter/j/f475e1/32.png) [@jakobtahe](https://discuss.elastic.co/u/jakobtahe)\
**Post date:** [March 23, 2020, 8:16pm UTC](https://discuss.elastic.co/t/filtering-for-multiple-values-in-a-single-field/224627/3 "2020-03-23T20:16:20Z")

</div>

Thanks so much for your very informative answer and I will try this out to re-structure the data ingestion from Logstash and see if it will work but it really seams that it should work.

---

<div class="post-metadata">

**Author:** ![jakobtahe](https://avatars.discourse-cdn.com/v4/letter/j/f475e1/32.png) [@jakobtahe](https://discuss.elastic.co/u/jakobtahe)\
**Post date:** [March 31, 2020, 2:20pm UTC](https://discuss.elastic.co/t/filtering-for-multiple-values-in-a-single-field/224627/4 "2020-03-31T14:20:44Z")

</div>

Is there any documentation on how to structure the index as in the `customers` example above?

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2020, 2:20pm UTC](https://discuss.elastic.co/t/filtering-for-multiple-values-in-a-single-field/224627/5 "2020-04-28T14:20:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
