# How to make data table of last value

**URL:** <https://discuss.elastic.co/t/how-to-make-data-table-of-last-value/285921>\
**Category:** Kibana\
**Created:** [October 5, 2021, 12:52pm UTC](https://discuss.elastic.co/t/how-to-make-data-table-of-last-value/285921 "2021-10-05T12:52:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [October 5, 2021, 12:52pm UTC](https://discuss.elastic.co/t/how-to-make-data-table-of-last-value/285921/1 "2021-10-05T12:52:46Z")

</div>

Hi,

Do you know how to create a data table with the laste value of every host (for example) ?

And is it possible to apply a filter based on last value ? (I dont want to see all hosts)

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [October 5, 2021, 1:41pm UTC](https://discuss.elastic.co/t/how-to-make-data-table-of-last-value/285921/2 "2021-10-05T13:41:57Z")

</div>

Hi @GinkoLucas ,

welcome to the Kibana community.  
Can you explain a little bit more what last value you want to show, and how the filters should work?  
A basic table example will suffice.

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [October 5, 2021, 1:54pm UTC](https://discuss.elastic.co/t/how-to-make-data-table-of-last-value/285921/3 "2021-10-05T13:54:45Z")

</div>

Hi @Marco_Liberati,

I store logs in Elastic. I want a data table who show me the last log sent by host.  
So each line represents a host and for example the last value of the level of the log (information, warning, error...).  
Like this :

HOST | LEVEL  
host 1 | Error  
host 2 | Information  
host 3 | Error  
host 4 | Warning

I already try to do this with "Top Hit" metric and "Last Value" metric in Lens, but i cannot apply filter on last value. I would like to display the hosts having "Error" as the last value of the level field :

HOST | LEVEL  
host 1 | Error  
host 3 | Error

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [October 5, 2021, 2:12pm UTC](https://discuss.elastic.co/t/how-to-make-data-table-of-last-value/285921/4 "2021-10-05T14:12:32Z")

</div>

It is not possible to hide the lines, but if you click on `Add Advanced options` and click on filter by, you can filter by `level: Error` in your case.

![Screenshot 2021-10-05 at 16.10.34](https://us1.discourse-cdn.com/elastic/original/3X/a/d/ad27b292d9594112b5d3727b7aebffa7f037c210.png)

Then clicking on the Table column `Level` header you can sort in ascending order and the hosts with the `Error` level will always be the first ones.

 ![Screenshot 2021-10-05 at 16.12.14](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f90beb66bd379fbcf79e93715e3ee803c02e9d25.png)

Would that work?

---

<div class="post-metadata">

**Author:** ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Post date:** [October 5, 2021, 2:19pm UTC](https://discuss.elastic.co/t/how-to-make-data-table-of-last-value/285921/5 "2021-10-05T14:19:36Z")

</div>

Thanks @Marco_Liberati.

It's not exactly what I would like, but if there is no other way it should be enough.

Thanks for taking time for me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2021, 2:19pm UTC](https://discuss.elastic.co/t/how-to-make-data-table-of-last-value/285921/6 "2021-11-02T14:19:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
