# Group by function in Discover

**URL:** <https://discuss.elastic.co/t/group-by-function-in-discover/305922>\
**Category:** Kibana\
**Created:** [May 30, 2022, 9:06am UTC](https://discuss.elastic.co/t/group-by-function-in-discover/305922 "2022-05-30T09:06:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![temp\_account](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@temp\_account](https://discuss.elastic.co/u/temp_account)\
**Post date:** [May 30, 2022, 9:06am UTC](https://discuss.elastic.co/t/group-by-function-in-discover/305922/1 "2022-05-30T09:06:30Z")

</div>

i used a lot of Kibana/Discover in work.  
As you know, in the query result of Discover, in each log record, there may be many fields included, eg. userid, flowid, userip, username, userAction, etc.  
Several log record may be correlated by some fields, eg. userid / flowid.  
If i search by flowid, i can get logs relating to one flowid, this is easy to investigate log payload.  
If i search by userid, i can get logs relating to one user, but maybe several flows, at this case, i can see lots of plain text on the page, it is not easy to investigate log payload.

Is there a function that i can define one or several fields as Group by key (eg. flowid) , when this key applies, in the Discover query result page (query by userid), the logs are grouped by the key (flowid) and organized, so that i can investigate flow one by one for this user?

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [May 31, 2022, 2:11pm UTC](https://discuss.elastic.co/t/group-by-function-in-discover/305922/2 "2022-05-31T14:11:06Z")

</div>

We do have this enhancement on the backlog [[Discover] Group by field(s) · Issue #103008 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/103008)

You can use a Lens table to build this sort of exploration in the short term before we deliver the above functionality

---

<div class="post-metadata">

**Author:** ![temp\_account](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@temp\_account](https://discuss.elastic.co/u/temp_account)\
**Post date:** [June 1, 2022, 8:10am UTC](https://discuss.elastic.co/t/group-by-function-in-discover/305922/3 "2022-06-01T08:10:28Z")

</div>

Thanks.  
Actually we have built our own frontend UI to display the ES log queryed by API, which greatly improved our work efficiency. So this feature is not in emergency for us now. Glad to here it was in consideration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2022, 8:11am UTC](https://discuss.elastic.co/t/group-by-function-in-discover/305922/4 "2022-06-29T08:11:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
