# How to filter with a few value?

**URL:** <https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204>\
**Category:** Kibana\
**Created:** [January 19, 2018, 10:06am UTC](https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204 "2018-01-19T10:06:29Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Loczeski](https://avatars.discourse-cdn.com/v4/letter/l/cab0a1/32.png) [@Loczeski](https://discuss.elastic.co/u/Loczeski)\
**Post date:** [January 19, 2018, 10:06am UTC](https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204/1 "2018-01-19T10:06:29Z")

</div>

I have this filter, but it searchs just a one IP. How to and another IP to search e.g "[bb.bb.bbb.bb](http://bb.bb.bbb.bb)"?  
It is possible?

{  
"query": {  
"match": {  
"ip": {  
"query":"[xx.xxx.xxx.xxx](http://xx.xxx.xxx.xxx)",  
"type": "phrase"  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [January 19, 2018, 3:53pm UTC](https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204/2 "2018-01-19T15:53:08Z")

</div>

In the filter editor UI, use the "is one of" option:

 ![28 AM](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e32e8b10c8eab8bc264009db8a1702193540550.png)

---

<div class="post-metadata">

**Author:** ![Loczeski](https://avatars.discourse-cdn.com/v4/letter/l/cab0a1/32.png) [@Loczeski](https://discuss.elastic.co/u/Loczeski)\
**Post date:** [January 19, 2018, 4:11pm UTC](https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204/3 "2018-01-19T16:11:18Z")

</div>

Ok but how to do when he have e.g 50 values to filtr? Copy/past doesnt work.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [January 19, 2018, 4:57pm UTC](https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204/4 "2018-01-19T16:57:34Z")

</div>

Yeah, there isn't a great way to do that at the moment. You can click "Edit Query DSL" and modify the JSON with copy/paste, but that's not ideal. Please feel free to open an enhancement request on our [github repo](https://github.com/elastic/kibana).

---

<div class="post-metadata">

**Author:** ![Loczeski](https://avatars.discourse-cdn.com/v4/letter/l/cab0a1/32.png) [@Loczeski](https://discuss.elastic.co/u/Loczeski)\
**Post date:** [January 22, 2018, 7:17am UTC](https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204/5 "2018-01-22T07:17:37Z")

</div>

Thanks! Can we filter without duplicate ? I have a few record with the same IP, and I need to filter without duplicate IP. Can we do this ?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [January 22, 2018, 3:30pm UTC](https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204/6 "2018-01-22T15:30:28Z")

</div>

Sorry, I'm not sure what you mean exactly, can you elaborate?

---

<div class="post-metadata">

**Author:** ![Loczeski](https://avatars.discourse-cdn.com/v4/letter/l/cab0a1/32.png) [@Loczeski](https://discuss.elastic.co/u/Loczeski)\
**Post date:** [January 23, 2018, 7:33am UTC](https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204/7 "2018-01-23T07:33:33Z")

</div>

When I use filtr "IP" - The kibana finds me e.g 100 logs.  
The logs has differents values but some logs has the same IP.  
I just need to use some filtr becasue I would to see logs without duplicate IP.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [January 23, 2018, 4:41pm UTC](https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204/8 "2018-01-23T16:41:02Z")

</div>

So you'd only like to see documents that contain an IP that is unique to that single document?

If my understanding of the question is correct, this is a tough one to solve. There isn't a good way to automatically filter out duplicates. Depending on your data and use case, you might be able to first create a visualization with a terms agg on the IP field and a `min_doc_count` of 2. This would find all the IPs that appear more than once. You could then grab all those IPs and manually create a filter that filters them out. It's not a great solution, but maybe it could work for you.

In the future we'd like to enhance Kibana so that it could do these types of multi-step queries automatically.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2018, 4:41pm UTC](https://discuss.elastic.co/t/how-to-filter-with-a-few-value/116204/9 "2018-02-20T16:41:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
