# How do I get unique values from a field with a given search in kibana

**URL:** <https://discuss.elastic.co/t/how-do-i-get-unique-values-from-a-field-with-a-given-search-in-kibana/272621>\
**Category:** Kibana\
**Created:** [May 11, 2021, 12:55am UTC](https://discuss.elastic.co/t/how-do-i-get-unique-values-from-a-field-with-a-given-search-in-kibana/272621 "2021-05-11T00:55:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![KS\_123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ks_123/32/81648_2.png) [@KS\_123](https://discuss.elastic.co/u/KS_123)\
**Post date:** [May 11, 2021, 12:55am UTC](https://discuss.elastic.co/t/how-do-i-get-unique-values-from-a-field-with-a-given-search-in-kibana/272621/1 "2021-05-11T00:55:45Z")

</div>

If I have a given search:  
eventType:DeviceRequestResponseEvent  
AND (_exists_:payload.cattle.name)  
AND DoorId:1bf35dbc-ce2b-4a2c-b126-7cd531aa84ad  
AND payload.deviceRequestResponseEvent.payloadType:COMMAND\_REQUEST\_TYPE  
AND NOT payload.deviceRequestResponseEvent.responseCode:SUCCESS

And I want to find the unique values of a field, example below, not in the search above:  
payload.deviceRequestResponseEvent.responseCode

So the values from `payload.deviceRequestResponseEvent.responseCode` might be  
abc  
def  
ghi

How do I do this in kibana or in the serach part of kibana

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 11, 2021, 1:24am UTC](https://discuss.elastic.co/t/how-do-i-get-unique-values-from-a-field-with-a-given-search-in-kibana/272621/2 "2021-05-11T01:24:36Z")

</div>

2 steps that should get what you want;

1. Setup a filter with those terms
2. Use a terms aggregation on that field, with a unique metric

This will likely be best displayed as a table.

---

<div class="post-metadata">

**Author:** ![KS\_123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ks_123/32/81648_2.png) [@KS\_123](https://discuss.elastic.co/u/KS_123)\
**Post date:** [May 12, 2021, 10:26pm UTC](https://discuss.elastic.co/t/how-do-i-get-unique-values-from-a-field-with-a-given-search-in-kibana/272621/3 "2021-05-12T22:26:16Z")

</div>

tks, but  
I add my search in kibana -\> discover  
Then I add my filter with field name `payload.deviceRequestResponseEvent.responseCode`  
but this only allows me to filter on field and there is an operator but this include "is, isnot ...exists"but there is no unique operator.

In the edit filter there is a `edit as query DSL`, maybe i can write a script there, tho not familiar with that language.

Maybe you are referring to the create viualisation, which I have created a table in there, which I have worked out how to get the unique values of a field but that is just on the field, I can't apply a search/filter before getting the unique values of a chosen field. tks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 12, 2021, 10:27pm UTC](https://discuss.elastic.co/t/how-do-i-get-unique-values-from-a-field-with-a-given-search-in-kibana/272621/4 "2021-05-12T22:27:14Z")

</div>

You need to create a visualisation, usually in a dashboard. Discover is only for filtering as you have found.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2021, 10:27pm UTC](https://discuss.elastic.co/t/how-do-i-get-unique-values-from-a-field-with-a-given-search-in-kibana/272621/5 "2021-06-09T22:27:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
