# How to merge two search values two a single one

**URL:** <https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590>\
**Category:** Kibana\
**Created:** [May 27, 2020, 4:42pm UTC](https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590 "2020-05-27T16:42:55Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matish\_Bhuyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matish_bhuyan/32/68043_2.png) [@Matish\_Bhuyan](https://discuss.elastic.co/u/Matish_Bhuyan)\
**Post date:** [May 27, 2020, 4:42pm UTC](https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590/1 "2020-05-27T16:42:55Z")

</div>

Hi All,

I have one improvement task.

For example i have one keyword in kibana called fruits

so i need to search the different fruits names say apple and orange and got two count values say A and B for each respective fruit.

but in visualization i don't want the results to be visualized as

apple 5  
orange 6

instead i want to merge the count of the these 2 search values to a new one called  
**fruits** and it will show the count as 11.

it should come like

fruits 11

in Kibana visualization instead of the previous one shown above.

but I want to merge the values of both to a new value say C,

How to do that using Kibana scripted field or making changes in the logstash configuration?

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 27, 2020, 5:19pm UTC](https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590/2 "2020-05-27T17:19:56Z")

</div>

Hello @Matish_Bhuyan

If we were on Elasticsearch DSL, we could use the `value count` aggregation.

## Demo data

```auto
PUT discuss/_doc/1
{
  "timestamp" : "2020-01-19T03:26:21.326Z",
  "fruits": "banana"
}
PUT discuss/_doc/2
{
  "timestamp" : "2020-01-19T03:26:21.326Z",
  "fruits": "banana"
}
PUT discuss/_doc/3
{
  "timestamp" : "2020-01-19T03:26:21.326Z",
  "fruits": "apple"
}
PUT discuss/_doc/4
{
  "timestamp" : "2020-01-19T03:26:21.326Z",
  "fruits": ["apple", "banana", "orange"]
}

```

## Query

```auto
GET discuss/_search
{
  "aggs": {
    "total": {
      "value_count": {
        "field": "fruits.keyword"
      }
    }
  }
}

```

# Kibana

On Kibana, the `value_count` aggregation is exposed only in TSVB.

I've tried to put in place an example, but it seems there's a problem (at least on 7.7.0).

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9f636a6e1a6990a5aec208d257922fc2ea94c750.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/a/fa980b07d350fb745468aa703fcb729449f7d3bd.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/0/8097da0fc9fc14fd29d68e129d8ed91c768ade93.png)

The `fruits.keyword` field doesn't show up in `Field`.

It seems we have an open issue to track the support for `value_count` in traditional visualizations

> <https://github.com/elastic/kibana/issues/67403>
>
> Part of #60126
> This issue tracks support for value count aggregations in AggConfigs. Adding this agg type will unblock apps like Visualize...

But as I see the `value_count` in TSVB, I would expect to work... Sorry to ping @lukeelmers - Is this expected?

---

<div class="post-metadata">

**Author:** ![Matish\_Bhuyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matish_bhuyan/32/68043_2.png) [@Matish\_Bhuyan](https://discuss.elastic.co/u/Matish_Bhuyan)\
**Post date:** [May 27, 2020, 9:56pm UTC](https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590/3 "2020-05-27T21:56:26Z")

</div>

Hi Luca,

Thanks a lot for the response and the example,

But we have a fruit keyword which is created and the only thing is we are populating different value to get the total count.

My issue is this -- I have one keyword named as service where i get two different values.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e50ff81d01db8a22fa9056d8f6853dc698f1532.png)

this is how my data table looks now

But i want a filter value in kibana or logstash that both the service.keyword output as you see should be merged to a new , Which will be called as -- \> FIRST NID CARD and also the count of both the values should be added to it.

---

<div class="post-metadata">

**Author:** ![Matish\_Bhuyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matish_bhuyan/32/68043_2.png) [@Matish\_Bhuyan](https://discuss.elastic.co/u/Matish_Bhuyan)\
**Post date:** [May 27, 2020, 9:58pm UTC](https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590/4 "2020-05-27T21:58:18Z")

</div>

and i am using the elastic search version 7.2

And i can't upgrade to the recent version which is 7.7

---

<div class="post-metadata">

**Author:** ![Matish\_Bhuyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matish_bhuyan/32/68043_2.png) [@Matish\_Bhuyan](https://discuss.elastic.co/u/Matish_Bhuyan)\
**Post date:** [May 27, 2020, 11:04pm UTC](https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590/5 "2020-05-27T23:04:23Z")

</div>

thanks Luca

I have resolved the issue now by adding this in the filter section of logstash config

if [keyword.value] in ["x", "y"]  
{  
mutate {  
update =\> { "keyword.value" =\> "z" }  
}

if [groceries] in ["apple", "orange"]  
{  
mutate {  
update =\> { "groceries" =\> "fruits" }  
}

so if now the individual apple and orange search value is updated to fruits  
and also their individual count value too comes to the fruits count value.

so before update my dashboard looks like  
apple 5  
orange 6

After update the filter option my dashboard is  
fruits 11

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [May 28, 2020, 2:42am UTC](https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590/6 "2020-05-28T02:42:52Z")

</div>

@Luca_Belluccini If you are running into issues with value count in TSVB then it sounds like a potential bug... currently TSVB is the one place we expect value count aggs to work in Kibana.

There is an Aggs Support in Kibana meta issue which is helpful in understanding where you can expect to find support for various agg types: [https://github.com/elastic/kibana/issues/58628](https://github.com/elastic/kibana/issues/58628)

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 28, 2020, 8:06am UTC](https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590/7 "2020-05-28T08:06:52Z")

</div>

Thank you Luke

I've opened:

> <https://github.com/elastic/kibana/issues/67581>
>
> Kibana version: 7.6.2, 7.7.0 (probably more versions affected)
> Elasticsearch version: 7.6.2, 7.7.0
> Describe the bug:
> When using TSVB and we want to use the...

@Matish_Bhuyan , while your question helped us to identify a Kibana issue (Thanks 😃 )

If I understood correctly from the first question, you have/had documents such as:

```auto
PUT discuss/_doc/1
{
  "timestamp" : "2020-01-19T03:26:21.326Z",
  "fruits": "banana"
}
PUT discuss/_doc/2
{
  "timestamp" : "2020-01-19T03:26:21.326Z",
  "fruits": "banana"
}
PUT discuss/_doc/3
{
  "timestamp" : "2020-01-19T03:26:21.326Z",
  "fruits": "apple"
}
PUT discuss/_doc/4
{
  "timestamp" : "2020-01-19T03:26:21.326Z",
  "fruits": ["apple", "banana", "orange"]
}

```

And you wanted to get 3 as count, instead of obtaining the count, split by terms.  
The correct way to handle this, without modifying the structure of the document with Logstash, would be to use `value_count` aggregation.

Once the bug I just opened will be fixed, you'll be able to select `service.keyword` and it would output the count of values, without splitting them in the different values.

If you take the time to run the query:

```auto
GET discuss/_search
{
  "aggs": {
    "total": {
      "value_count": {
        "field": "fruits.keyword"
      }
    }
  }
}

```

You will see we obtain 6 (given the demo data I've shared).

* * *

That said, you are free to solve the issue using Logstash, but you have to know all the different values you might have in the field, which is not always possible.

---

<div class="post-metadata">

**Author:** ![Matish\_Bhuyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matish_bhuyan/32/68043_2.png) [@Matish\_Bhuyan](https://discuss.elastic.co/u/Matish_Bhuyan)\
**Post date:** [May 28, 2020, 8:36pm UTC](https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590/8 "2020-05-28T20:36:12Z")

</div>

Yes ,Thanks @Luca_Belluccini lot for the other option to fix the issue through the lucene syntax.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2020, 8:36pm UTC](https://discuss.elastic.co/t/how-to-merge-two-search-values-two-a-single-one/234590/9 "2020-06-25T20:36:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
