# How to create a table with index content as column title and count as content?

**URL:** <https://discuss.elastic.co/t/how-to-create-a-table-with-index-content-as-column-title-and-count-as-content/76949>\
**Category:** Kibana\
**Created:** [March 1, 2017, 9:02am UTC](https://discuss.elastic.co/t/how-to-create-a-table-with-index-content-as-column-title-and-count-as-content/76949 "2017-03-01T09:02:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [March 1, 2017, 9:02am UTC](https://discuss.elastic.co/t/how-to-create-a-table-with-index-content-as-column-title-and-count-as-content/76949/1 "2017-03-01T09:02:36Z")

</div>

Hi,

I use ELk GA 5.0.0. I have log entries like below

```
<timestamp><user><action>

```

Which is parsed by logstash and saved to elasticsearch. Actions can be like `login`, `search`, `logout` etc. I wanted to view total count of actions of each user. I was able to create a table visualization in Kibana like below;

```
-----------------------------
User | Action | Count
-------+------------+--------
UserA | Login | 20
-------+------------+--------
UserA | Search | 10
-------+------------+--------
UserB | Login | 10
-------+------------+--------
UserB | Search | 5
-------+------------+--------
UserC | Login | 5
-------+------------+--------
UserC | Search | 2
-----------------------------

```

But, I would like to create a table like below;

```
--------------------------
User | Login | Search
-------+---------+--------
UserA | 20 | 10
-------+---------+--------
UserB | 10 | 5
-------+---------+--------
UserC | 5 | 2
--------------------------

```

Is this possible in Kibana?

Thanks in advance..

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [March 1, 2017, 7:27pm UTC](https://discuss.elastic.co/t/how-to-create-a-table-with-index-content-as-column-title-and-count-as-content/76949/2 "2017-03-01T19:27:41Z")

</div>

You could do this a couple ways, one of which would be a scripted field.

Create two scripted fields: `Login` and `Search` with scripts that look something like this:

```auto
doc['Action'].value == 'Login' ? 1 : 0

```

Then use two metric aggregations for `Sum of Login` and `Sum of Search`.

---

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [March 1, 2017, 7:58pm UTC](https://discuss.elastic.co/t/how-to-create-a-table-with-index-content-as-column-title-and-count-as-content/76949/3 "2017-03-01T19:58:55Z")

</div>

Hi, Thanks for your reply.

But @spalger , I have a saved search, which only returns `Login` and `Search` values, and I have linked my table to that search, so that only Login and Search will be displayed. My question is, whether the so called "scripted field" is implemented for this purpose? If I have a saved search like this, how can I use two metric aggregations?

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [March 1, 2017, 9:18pm UTC](https://discuss.elastic.co/t/how-to-create-a-table-with-index-content-as-column-title-and-count-as-content/76949/4 "2017-03-01T21:18:55Z")

</div>

The metric aggregations are defined at the top of the aggregation sidebar in Visualize. Your current table uses a single "Count" aggregation, but change that to "Sum" and then choose either of your scripted fields in the new field drop down that shows up

---

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [March 2, 2017, 8:31am UTC](https://discuss.elastic.co/t/how-to-create-a-table-with-index-content-as-column-title-and-count-as-content/76949/5 "2017-03-02T08:31:30Z")

</div>

Thanks.. It helped.. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2017, 8:31am UTC](https://discuss.elastic.co/t/how-to-create-a-table-with-index-content-as-column-title-and-count-as-content/76949/6 "2017-03-30T08:31:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
