# Group by data in data table kibana \[Solved\]

**URL:** <https://discuss.elastic.co/t/group-by-data-in-data-table-kibana-solved/92465>\
**Category:** Kibana\
**Created:** [July 10, 2017, 12:24pm UTC](https://discuss.elastic.co/t/group-by-data-in-data-table-kibana-solved/92465 "2017-07-10T12:24:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chemse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chemse/32/17956_2.png) [@Chemse](https://discuss.elastic.co/u/Chemse)\
**Post date:** [July 10, 2017, 12:24pm UTC](https://discuss.elastic.co/t/group-by-data-in-data-table-kibana-solved/92465/1 "2017-07-10T12:24:50Z")

</div>

hello,

I need some help please  
how can I group data in this table to show them just in one row **group by \_type**

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8c42954f4b9a549515cf43d41f4c4df7803c946a.png)

my filter configuration is the following

```
filter {
		mutate {
			add_field => {	
				"heureDeDebut" => ""
				"heureDeFin" => ""
				"codeDeRetour" => ""
			}
		}
		grok {
			match => ["path", "/appli/exploit/logs/%{NOTSPACE:name}"]
		}
		mutate{
			add_field => { "type" => "%{name}" }
		}
		if "[INFO]: Heure de début du script" in [message] {
			csv {
				separator => ": "
				columns => ["A","B","heureDeDebut"]
				remove_field => ["A","B"]
			}
		} else if "[INFO]: Heure de fin du script" in [message]{
			csv {
				separator => ": "
				columns => ["A","B","heureDeFin"]
				remove_field => ["A","B"]
			}
		} else if "[INFO]: Code retour général du script" in [message]{
			csv {
				separator => ": "
				columns => ["A","B","codeDeRetour"]
				remove_field => ["A","B"]
			}
		} else { drop {} }
}

```

I don't kwon if I've to change my filter or play with kibana ???  
Help please 🙂

Thanks

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [July 10, 2017, 6:15pm UTC](https://discuss.elastic.co/t/group-by-data-in-data-table-kibana-solved/92465/2 "2017-07-10T18:15:23Z")

</div>

I think you can do this by using multiple top hit metrics.

e.g.:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/8/78996d7ad71ff11ea805e1845c02df5cd64b4c76.png)

As opposed to multiple buckets:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8b6719cc84eb7cb099aadf7d6bd4b13138a8ce3c.png)

---

<div class="post-metadata">

**Author:** ![Chemse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chemse/32/17956_2.png) [@Chemse](https://discuss.elastic.co/u/Chemse)\
**Post date:** [July 11, 2017, 8:10am UTC](https://discuss.elastic.co/t/group-by-data-in-data-table-kibana-solved/92465/3 "2017-07-11T08:10:45Z")

</div>

Thanks,

but I've problem with the comma, it shows `value,-,-` wich aggregation did you choose ??

for the line wich content the variable a , the other variables did exist ?? like an empty string ?? or doesn't existe at all for the same line ?

![](https://us1.discourse-cdn.com/elastic/original/3X/b/a/ba5bc3b993ee00f96abdb0712650148d9e46e564.png)

thanks 🙂

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [July 11, 2017, 2:13pm UTC](https://discuss.elastic.co/t/group-by-data-in-data-table-kibana-solved/92465/4 "2017-07-11T14:13:47Z")

</div>

Ah, scratch that, you can't do it with `top hit` metric (that is the metric aggregation I choose). It may have only worked in my example because of a fluke, or because I didn't have a time field. The Top Hit metric chooses the most recent value in the document, which may be an empty string. It's almost as if you want `Max` metric but on a string field, not a numeric field, but that doesn't exist.

Unfortunately I'm not aware of a way to achieve what you are looking for. I think your best bet may be to try and combine the rows at index time, so instead of indexing a separate document for each field, you index a single document with all the fields filled in.

---

<div class="post-metadata">

**Author:** ![Chemse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chemse/32/17956_2.png) [@Chemse](https://discuss.elastic.co/u/Chemse)\
**Post date:** [July 11, 2017, 3:52pm UTC](https://discuss.elastic.co/t/group-by-data-in-data-table-kibana-solved/92465/5 "2017-07-11T15:52:23Z")

</div>

Thank you so much, I choosed Top Hit and it woks 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2017, 3:52pm UTC](https://discuss.elastic.co/t/group-by-data-in-data-table-kibana-solved/92465/6 "2017-08-08T15:52:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
