# Help building data table report

**URL:** <https://discuss.elastic.co/t/help-building-data-table-report/134479>\
**Category:** Kibana\
**Created:** [June 4, 2018, 7:28pm UTC](https://discuss.elastic.co/t/help-building-data-table-report/134479 "2018-06-04T19:28:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dan\_gold](https://avatars.discourse-cdn.com/v4/letter/d/67e7ee/32.png) [@dan\_gold](https://discuss.elastic.co/u/dan_gold)\
**Post date:** [June 4, 2018, 7:28pm UTC](https://discuss.elastic.co/t/help-building-data-table-report/134479/1 "2018-06-04T19:28:20Z")

</div>

Hi everyone. I am trying to create a data table based on the sample logstash indeces provided [here](https://www.elastic.co/guide/en/kibana/current/tutorial-load-dataset.html). I want the table to follow the following format:

Term/Keyword | # Total | # 200 (response) | # 404 (response) | # 503 (response)  
IP Address (IP)   
jpg (extension)   
css (extension)   
png (extension)   
gif (extension)   
php (extension)

Basically, I want to get total count of IP addresses across all events and the total count of each extension across all events. In addition, I want the same breakdown filtered on each response keyword.

I'm close (please see the attached screenshots), but I want it to match the format I outlined above.

Any help would be greatly appreciated!

 ![config](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b6a27598300f4824436f9a299c81e83d4f08524.png) ![data_table](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d5318baa76bde904de1f7676be1a9256b72a2d4d.png) ![option](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0f5bd987d4e08d80a5860b3ac6343aafe8e10a5b.png)

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [June 4, 2018, 8:58pm UTC](https://discuss.elastic.co/t/help-building-data-table-report/134479/2 "2018-06-04T20:58:13Z")

</div>

One possible solution would be to use a scripted field to determine if it's an event you want to include and sum them.

Example scripted field:

```auto
if (doc['response.keyword'].value.startsWith('2')) {
  return 1;
}

```

You can add this from the Index Pattern detail page.

 ![52](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a36a9b417b96b0697fef099152f756ef1872dff8.png)

---

<div class="post-metadata">

**Author:** ![dan\_gold](https://avatars.discourse-cdn.com/v4/letter/d/67e7ee/32.png) [@dan\_gold](https://discuss.elastic.co/u/dan_gold)\
**Post date:** [June 5, 2018, 2:49pm UTC](https://discuss.elastic.co/t/help-building-data-table-report/134479/3 "2018-06-05T14:49:37Z")

</div>

Thank you! That works perfectly. Looks like I've got to learn Painless.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2018, 2:57pm UTC](https://discuss.elastic.co/t/help-building-data-table-report/134479/4 "2018-07-03T14:57:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
