# How to filter by "Count of records" within Kibana Lens

**URL:** <https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197>\
**Category:** Kibana\
**Tags:** lens\
**Created:** [June 16, 2023, 8:38am UTC](https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197 "2023-06-16T08:38:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![fim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fim/32/90645_2.png) [@fim](https://discuss.elastic.co/u/fim)\
**Post date:** [June 16, 2023, 8:38am UTC](https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197/1 "2023-06-16T08:38:16Z")

</div>

My goal is to filter by counts for a field "tracking\_no" where the value inside of the field is exactly similar.

In Kibana Lens I created a simple table with a count aggregation. The table show exactly what I expect, but the goal is to filter out the Count of records = 1. Only show lines with count = 2.

Is it possible within Kibana to filter by the aggregation field in my case "Count of records"?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/9541aa68c97c510a474b2626b9f9e8ec414dcbb5.png)

Alternatively I tried with a runtime field, but it doesn't what I expect:

```auto
PUT /my-*/_mapping
{
  "runtime": {
    "count_field": {
      "type": "long",
      "script": {
        "source": """
          if (doc.containsKey('sa_tracking_no.keyword') && doc['sa_tracking_no.keyword'].size() == "2") {
            emit(1L);
          } else {
            emit(0L);
          }
        """
      }
    }
  }
}

```

The runtime field results always in "0" even when we have pairs of documents with similar field value.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b4a76e048f9a6aa87031bdcbb18a8a5b376bf67.png)

---

<div class="post-metadata">

**Author:** ![Marta\_Bondyra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_bondyra/32/102122_2.png) [@Marta\_Bondyra](https://discuss.elastic.co/u/Marta_Bondyra)\
**Post date:** [June 20, 2023, 9:07am UTC](https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197/2 "2023-06-20T09:07:37Z")

</div>

Hello,

Unfortunately, I don't think it's possible at the moment. We can only filter by non-aggregated data for now.  
Runtime field solution doesn't work either because runtime field don't work between documents – they are calculated for each document separately.

---

<div class="post-metadata">

**Author:** ![fim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fim/32/90645_2.png) [@fim](https://discuss.elastic.co/u/fim)\
**Post date:** [June 27, 2023, 6:43am UTC](https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197/3 "2023-06-27T06:43:47Z")

</div>

Thanks for your feedback Marta. 😞

I found a way with a scripted query to filter by docCount.  
But do you know how to implement a script in Kibana?

my-\* is again the combined index.

```auto
POST /my-*/_search
{
  "size": 0,
  "query": {
    "match_all": {}
  },
  "aggs": {
    "field_value_count": {
      "terms": {
        "field": "sa_tracking_no.keyword",
        "size": 10
      },
      "aggs": {
        "doc_count_filter": {
          "bucket_selector": {
            "buckets_path": {
              "docCount": "_count"
            },
            "script": "params.docCount == 2"
          }
        }
      }
    }
  }
}

```

Can't believe that there is no way to filter by docCount in an index?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f056e07486f74e207cf7b6a1634b2fd38e41a3c5.jpeg)

---

<div class="post-metadata">

**Author:** ![Marta\_Bondyra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_bondyra/32/102122_2.png) [@Marta\_Bondyra](https://discuss.elastic.co/u/Marta_Bondyra)\
**Post date:** [June 27, 2023, 11:10am UTC](https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197/4 "2023-06-27T11:10:35Z")

</div>

There's a way to do it in Vega (not trivial though, but you have a lot of flexibility there) or in TSVB (but comes with a set of disadvantages, like the invisible rows would still occupy space). Here's the example of configured panel:

 ![Screenshot 2023-06-27 at 13.09.54](https://us1.discourse-cdn.com/elastic/original/3X/0/7/079894a2f16472dd0d1bf5518d625b280af9d0ae.png)

We have plans to add it in the future in Lens but we're not there yet.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2023, 11:11am UTC](https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197/5 "2023-07-25T11:11:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
