# How to remove values from a returned search if they are equal?

**URL:** <https://discuss.elastic.co/t/how-to-remove-values-from-a-returned-search-if-they-are-equal/226544>\
**Category:** Kibana\
**Created:** [April 4, 2020, 11:16pm UTC](https://discuss.elastic.co/t/how-to-remove-values-from-a-returned-search-if-they-are-equal/226544 "2020-04-04T23:16:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mds4872](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mds4872/32/47241_2.png) [@mds4872](https://discuss.elastic.co/u/mds4872)\
**Post date:** [April 4, 2020, 11:16pm UTC](https://discuss.elastic.co/t/how-to-remove-values-from-a-returned-search-if-they-are-equal/226544/1 "2020-04-04T23:16:56Z")

</div>

Hi yall,

I have traceroute data pointing to websites and I wanted to know how I could filter out responses if they are qual in hop length? For example, I have a job-id with attached http and https traceroutes, once each traceroute completes it returns a total-hops value. I want to filter out all job-id's where the total-hops value for https and http are equal. Below is an example of what the table format looks like for an https result. The Job-id remains the same for http. Basically for each job-id I want to find results where total-hops for http != https.

 ![Annotation 2020-04-04 185434](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d13ce4a563a920a3709e5cf609401bf848d83bc.png)

I also built a data table to also show what im looking to do. In this image, it is showing a count of total hops broken down by job-id and protocol.keyword. You can see that http and https hops are equal so I would like to exclude them from the visualization. I've tried messing around with the request field itself, but I can't seem to get it to exclude the job-id if the hop counts are equal. Any help or ideas would be appreciated!

 ![Annotation 2020-04-04 191023](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d0e23b97ac7ce6184070a1b9ee9c67e0d34f6cb.png)

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [April 7, 2020, 8:15pm UTC](https://discuss.elastic.co/t/how-to-remove-values-from-a-returned-search-if-they-are-equal/226544/2 "2020-04-07T20:15:40Z")

</div>

I don't think Kibana table cells are configurable in the way you're thinking. There are ways to craft requests to Elasticsearch that can apply scripts in sub-aggregations and calculate over the values of higher-level aggregations. Those scripts generally work by taking metric inputs and returning a metric output. One example is the Bucket Script aggregation. Various visualization types in Kibana are integrated with that aggregation type, and playing around with those aggregation types could help you move forward.

Another idea is to try a scripted field, or have a pre-processing step at data ingestion time that can calculate a new field out of the raw data that gives better semantic value. Right now, it seems like you're not sure when `http` / `https` counts are relevant for the visualization, but maybe you need a field that only exists when those counts are relevant, and can be used in the visualization in place of `http` / `https`.

Sorry, I'm not sure if these ideas apply directly to your use case, but maybe it can help rethink the problem in a way that's more natural to Elasticsearch aggregations: calculations have to be factored in at an early step.

---

<div class="post-metadata">

**Author:** ![mds4872](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mds4872/32/47241_2.png) [@mds4872](https://discuss.elastic.co/u/mds4872)\
**Post date:** [April 7, 2020, 8:35pm UTC](https://discuss.elastic.co/t/how-to-remove-values-from-a-returned-search-if-they-are-equal/226544/3 "2020-04-07T20:35:48Z")

</div>

Hi Tim,  
Thanks for the tips! We actually did end up with a pre-processing check from our redis db before we shipped the data to ELK. Now the data will have a boolean value that indicates whether there was a differnce in the hop counts or not, and we can just visualize the data using that boolean value. I think we couldve done it with a scripted field, but we were already doing a bunch of other pre-processing with python so it was easiest to just add the logic in there.

Thanks again for the help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2020, 8:35pm UTC](https://discuss.elastic.co/t/how-to-remove-values-from-a-returned-search-if-they-are-equal/226544/4 "2020-05-05T20:35:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
