# Filtering records in kibana based on conditions

**URL:** <https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634>\
**Category:** Kibana\
**Created:** [April 24, 2020, 11:28am UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634 "2020-04-24T11:28:33Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![anjilinga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anjilinga/32/86010_2.png) [@anjilinga](https://discuss.elastic.co/u/anjilinga)\
**Post date:** [April 24, 2020, 11:28am UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/1 "2020-04-24T11:28:33Z")

</div>

Hi, Can some one please help in the below scenario.  
I have the data 1000 records with each record is having 10 fields.  
I want to display the table with number of output fields.  
one out put field calculation is :  
field 3 = 12 or 13 or 14 and filed 4 = 1 or 2  
I am using sum bucket metric aggregation and filters, It is not giving correct results in the combination.  
when i use field 3 = 12 or 13 or 14 in one filter and by adding another filter for field 4=1 or 2  
it is giving the total records for each filter instead of evaluating the whole condition

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a5d6bd54d538dc97584660fbe3c2416124fda316.png)

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [April 24, 2020, 1:07pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/2 "2020-04-24T13:07:27Z")

</div>

Hello @anji

Could you provide a sample document and show the calculation you wish to perform? It sounds to me like you wish to perform a calculation with two fields as inputs but I'm not sure if you wish to perform any calculations between documents.

Thanks,  
Matt

---

<div class="post-metadata">

**Author:** ![anjilinga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anjilinga/32/86010_2.png) [@anjilinga](https://discuss.elastic.co/u/anjilinga)\
**Post date:** [April 24, 2020, 3:03pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/3 "2020-04-24T15:03:17Z")

</div>

Hi Matthew,  
Thanks for looking in to the issue.

The sample data is  
Callid State period accepted  
1 2 3 yes  
2 3 2 no  
3 1 4 no  
4 2 3 yes  
5 3 2 yes  
6 4 3 no

I want find the count of the records with **state** =2 or 3 and period =2 or 3 in the metric aggregation.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [April 24, 2020, 3:39pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/4 "2020-04-24T15:39:42Z")

</div>

You can add a filter to the visualization itself via the query bar in the visualization editor -

 ![Screen Shot 2020-04-24 at 10.38.57 AM](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6ff2c6a1c4396a7408243f60b258737d1aff47f7.png)

---

<div class="post-metadata">

**Author:** ![anjilinga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anjilinga/32/86010_2.png) [@anjilinga](https://discuss.elastic.co/u/anjilinga)\
**Post date:** [April 24, 2020, 3:41pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/5 "2020-04-24T15:41:36Z")

</div>

Hi Matthew,

it is one of the field in data table. if i apply in search bar it will apply for all the metrics in the table which is not fulfill my equirement.

Even in search bar it is not giving correct result with and and or condition in one query

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [April 24, 2020, 3:43pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/6 "2020-04-24T15:43:30Z")

</div>

I think you need to write the filter in such a way as to provide the desired result when run on all the documents

---

<div class="post-metadata">

**Author:** ![anjilinga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anjilinga/32/86010_2.png) [@anjilinga](https://discuss.elastic.co/u/anjilinga)\
**Post date:** [April 24, 2020, 3:46pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/7 "2020-04-24T15:46:04Z")

</div>

Hi Matthew,  
Even in search bar it is not giving correct result with and and or condition in one query

is there a way to filter with both or & and operations on two fields in one query to give the correct results

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [April 24, 2020, 3:47pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/8 "2020-04-24T15:47:57Z")

</div>

what query did you try and how did the result fail?

---

<div class="post-metadata">

**Author:** ![anjilinga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anjilinga/32/86010_2.png) [@anjilinga](https://discuss.elastic.co/u/anjilinga)\
**Post date:** [April 24, 2020, 3:54pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/9 "2020-04-24T15:54:37Z")

</div>

Hi Matthew,  
I want the result with the condition (state :2 or sate :3) and (period :2 or period :3)

while i entering in kibana it is taking as below  
state :2 or state:3 and period: 2 or period : 3

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [April 24, 2020, 4:02pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/10 "2020-04-24T16:02:49Z")

</div>

try (state :2 or state:3) and (period: 2 or period : 3)

---

<div class="post-metadata">

**Author:** ![anjilinga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anjilinga/32/86010_2.png) [@anjilinga](https://discuss.elastic.co/u/anjilinga)\
**Post date:** [April 27, 2020, 7:55pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/11 "2020-04-27T19:55:00Z")

</div>

Thanks Matthew it is working now

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2020, 8:03pm UTC](https://discuss.elastic.co/t/filtering-records-in-kibana-based-on-conditions/229634/12 "2020-05-25T20:03:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
