# Include filter from different modules

**URL:** <https://discuss.elastic.co/t/include-filter-from-different-modules/188095>\
**Category:** Kibana\
**Tags:** elastic-stack-graph\
**Created:** [June 28, 2019, 5:14pm UTC](https://discuss.elastic.co/t/include-filter-from-different-modules/188095 "2019-06-28T17:14:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [June 28, 2019, 5:14pm UTC](https://discuss.elastic.co/t/include-filter-from-different-modules/188095/1 "2019-06-28T17:14:23Z")

</div>

Hi

I am trying to create a graph to show number of people hitting our internal environments.

Version : ELK 7.2

Here I have installed filebeat on both Linux and windows environments.  
For windows I am using IIS module.  
For Linux I am using apache module.

Now I'm creating a single graph and showing users by split chart. My issue is I want to filter data base on the url access but data coming from Linux and Windows is different and I cant find a common value between these two.

**Linux**  
I can filter data by "url.original" is one of the following

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/6/36aed881e85a395d62a856d897ad4616dbfaa522.png)

**Windows**  
I can filter data by "url.path" is one of the following.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e27fb50d51e18b7a8c15670ec7ad253a63afb137.png)

What I can't do is show data where we have both "url.original" and "url.path". If I add two filters the dashboard is empty as expected.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c957a891a6ccf0891c079336a279bb13e6f030cc.png)

Can we have some condition with filter "X (or) Y" exists. (**if $url.path or $url.original) exists.** )  
Can you please tell me how I can achieve this.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [June 28, 2019, 5:34pm UTC](https://discuss.elastic.co/t/include-filter-from-different-modules/188095/2 "2019-06-28T17:34:57Z")

</div>

I was able to get it done as a dsl quiery. But it would have been nice I there was an option to select.

```
{
  "query": {
    "bool": {
      "should": [
        {
          "match_phrase": {
            "url.path": "/portal/home/"
          }
        },
        {
          "match_phrase": {
            "url.path": "/portal/sharing/rest/portals/self"
          }
        }
		{
          "match_phrase": {
            "url.original": "/portal/home/"
          }
        }
      ],
      "minimum_should_match": 1
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2019, 5:34pm UTC](https://discuss.elastic.co/t/include-filter-from-different-modules/188095/3 "2019-07-26T17:34:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
