How to find events with duplicate field value?


I have events which contains a numeric field
When I filter to be present for these events and aggregate for count and unique count I get different values.

I understand it this way, that one or some action.ids have a count of more than one.
Currently I am talking about 100,000 messages.

I need to retrieve all events, where the occurs in more than one event.
How do I do this?

Can I do it in kibana?

You should be able to do so with count but you may have to set the JSON input to { “min_doc_count”: 2 } in order to show values higher than 1. See example here Retrieve duplicate data using Kibana search bar.