# Finding a field's value using another field's value

**URL:** <https://discuss.elastic.co/t/finding-a-fields-value-using-another-fields-value/153127>\
**Category:** Kibana\
**Created:** [October 19, 2018, 7:28am UTC](https://discuss.elastic.co/t/finding-a-fields-value-using-another-fields-value/153127 "2018-10-19T07:28:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeremiguel](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jeremiguel](https://discuss.elastic.co/u/jeremiguel)\
**Post date:** [October 19, 2018, 7:28am UTC](https://discuss.elastic.co/t/finding-a-fields-value-using-another-fields-value/153127/1 "2018-10-19T07:28:35Z")

</div>

I'm a complete beginner with Kibana and Elasticsearch and I was wondering if I could use a field's value to find the value of another field.

Example:  
I have 10 logs in one index, and they all have a 'txn\_id' field and a 'log\_type' field.  
I want to find the 'txn\_id' of the logs with 'log\_type: "response"'.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [October 19, 2018, 3:55pm UTC](https://discuss.elastic.co/t/finding-a-fields-value-using-another-fields-value/153127/2 "2018-10-19T15:55:17Z")

</div>

Sure, just add a filter where `log_type` is `"response"` and then you can look through the records to see what the `txn_id` is. Or, you could create something like a tag cloud visualization, add the filter, and then do a terms aggregation on `txn_id` to see the top values for it.

---

<div class="post-metadata">

**Author:** ![jeremiguel](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jeremiguel](https://discuss.elastic.co/u/jeremiguel)\
**Post date:** [October 22, 2018, 1:56am UTC](https://discuss.elastic.co/t/finding-a-fields-value-using-another-fields-value/153127/3 "2018-10-22T01:56:23Z")

</div>

Hi Lukas, I appreciate the help above, but I don't think I typed out my question correctly. What I'd like to find out is how to find the txn\_id of the logs which have the log\_type "MER\_REQUEST", but do not have the log\_type "MER\_RESPONSE".

For example:  
A log with txn\_id, "ABC123" has 4 logs, with one being "MER\_REQUEST", another being "MER\_RESPONSE" and the remaining being other random log types.

Another log with txn\_id, "DEF456" has 6 logs, with one being "MER\_REQUEST" and the remaining being other random log types.

I'd like to find the logs like "DEF456" and have them displayed in a data table visualization, but I can't seem to find a method to do so.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 22, 2018, 5:28am UTC](https://discuss.elastic.co/t/finding-a-fields-value-using-another-fields-value/153127/4 "2018-10-22T05:28:52Z")

</div>

How do you link the different events? It might be easier for us to understand if you can show what the events actually look like rather than try to describe it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2018, 5:28am UTC](https://discuss.elastic.co/t/finding-a-fields-value-using-another-fields-value/153127/5 "2018-11-19T05:28:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
