# How to display duplicate values of a particular field in Kibana

**URL:** <https://discuss.elastic.co/t/how-to-display-duplicate-values-of-a-particular-field-in-kibana/58669>\
**Category:** Kibana\
**Created:** [August 23, 2016, 11:08am UTC](https://discuss.elastic.co/t/how-to-display-duplicate-values-of-a-particular-field-in-kibana/58669 "2016-08-23T11:08:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ishanim](https://avatars.discourse-cdn.com/v4/letter/i/51bf81/32.png) [@ishanim](https://discuss.elastic.co/u/ishanim)\
**Post date:** [August 23, 2016, 11:08am UTC](https://discuss.elastic.co/t/how-to-display-duplicate-values-of-a-particular-field-in-kibana/58669/1 "2016-08-23T11:08:43Z")

</div>

I have log data as follows:  
udp 81.0.0.1:1024 11.0.0.5:1024 --- ---  
udp 81.0.0.1:1024 11.0.0.5:1024 --- ---  
udp 81.0.0.1:1024 11.0.0.5:1024 --- ---  
udp 81.0.0.1:1024 11.0.0.5:1024 --- ---  
udp 81.0.0.1:1024 11.0.0.5:1024 --- ---  
udp 81.0.0.1:1024 11.0.0.5:1024 --- ---  
tcp 81.0.0.1:1024 11.0.0.5:52041 --- ---  
udp 81.0.0.1:1027 11.0.0.5:1027 --- ---  
udp 81.0.0.1:1026 11.0.0.5:1026 --- ---  
udp 81.0.0.1:1026 11.0.0.5:1026 --- ---  
udp 81.0.0.1:1026 11.0.0.5:1026 --- ---  
udp 81.0.0.1:1025 11.0.0.5:1025 --- ---

I need to display the count of all duplicate entries in Kibana.  
How can i do that ?

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [August 23, 2016, 7:36pm UTC](https://discuss.elastic.co/t/how-to-display-duplicate-values-of-a-particular-field-in-kibana/58669/2 "2016-08-23T19:36:13Z")

</div>

You first need to get your data into elasticsearch using [one of the beats](https://www.elastic.co/products/beats) or [logstash](https://www.elastic.co/products/logstash), but then once it's in elasticsearch a terms agg will count the number of times a specific term is found.

I would start by splitting those log lines into fields, something like `protocol`, `srcip`, `srcport`, `destip`, and `destport`. I would then run a terms aggregation on `protocol` to find how many of the logs were for `tcp` or `udp` and add a sub-aggregation for `destip` to see how many requests came to each uniq combination of `protocol` and `destip`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:40pm UTC](https://discuss.elastic.co/t/how-to-display-duplicate-values-of-a-particular-field-in-kibana/58669/3 "2017-07-06T13:40:30Z")

</div>


