# How to use kibana search and use aggregation

**URL:** <https://discuss.elastic.co/t/how-to-use-kibana-search-and-use-aggregation/195933>\
**Category:** Kibana\
**Created:** [August 20, 2019, 12:50pm UTC](https://discuss.elastic.co/t/how-to-use-kibana-search-and-use-aggregation/195933 "2019-08-20T12:50:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ashish\_Sikarwar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashish_sikarwar/32/47218_2.png) [@Ashish\_Sikarwar](https://discuss.elastic.co/u/Ashish_Sikarwar)\
**Post date:** [August 20, 2019, 12:50pm UTC](https://discuss.elastic.co/t/how-to-use-kibana-search-and-use-aggregation/195933/1 "2019-08-20T12:50:38Z")

</div>

Hello,

I am learning Lucene and Elasticsearch DSL.

I am using **Winlogbeat** and querying over field " **log.level**".  
How to use aggregation "Count" and group the data by **host** so i know the count for a specific host.

Without using Visualization, i am fetching the **count of events for 6 hours** see below:

> log.level: error

I get the following results:  
**Count 27**  
But there are multiple servers/hosts how can i get the following output:  
**Count 27 Host: XYZ\_SERVER**  
**Count 14 Host: ABC\_SERVER**  
**Count 20 Host: FGH\_SERVER**  
I may have to use aggregation and group the data by **host** so i know the count for a specific host:  
How can i get the "count" and group by "host.name"

I basically want to do something like this:  
Select count(log.level=error) from Winlogbeat group by host

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [August 20, 2019, 5:55pm UTC](https://discuss.elastic.co/t/how-to-use-kibana-search-and-use-aggregation/195933/2 "2019-08-20T17:55:52Z")

</div>

Hey @Ashish_Sikarwar, when you want to see aggregate information, you'll want to use a Visualization. If you'd like tabular output, the Data Table is the obvious candidate with a configuration like the following:

 ![37%20AM](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb36d03a82930784b5d9fcb41df18816d5e0652b.png)

---

<div class="post-metadata">

**Author:** ![Ashish\_Sikarwar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashish_sikarwar/32/47218_2.png) [@Ashish\_Sikarwar](https://discuss.elastic.co/u/Ashish_Sikarwar)\
**Post date:** [August 22, 2019, 10:02am UTC](https://discuss.elastic.co/t/how-to-use-kibana-search-and-use-aggregation/195933/3 "2019-08-22T10:02:18Z")

</div>

You are right @Brandon_Kobel , vIisualization is the right candidate, if i'd be using Kibana.  
But i will be issuing a query to Elasticsearch from a custom application.  
I could use ES Query and perform aggregation which works-

> log.level:error | agg:terms | field:fieldname size:10

Again thanks a lot for the reply!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2019, 10:02am UTC](https://discuss.elastic.co/t/how-to-use-kibana-search-and-use-aggregation/195933/4 "2019-09-19T10:02:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
