# Kibana 5, terms and aggregations

**URL:** <https://discuss.elastic.co/t/kibana-5-terms-and-aggregations/67744>\
**Category:** Kibana\
**Created:** [December 1, 2016, 10:43am UTC](https://discuss.elastic.co/t/kibana-5-terms-and-aggregations/67744 "2016-12-01T10:43:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nielsk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nielsk/32/7460_2.png) [@nielsk](https://discuss.elastic.co/u/nielsk)\
**Post date:** [December 1, 2016, 10:43am UTC](https://discuss.elastic.co/t/kibana-5-terms-and-aggregations/67744/1 "2016-12-01T10:43:59Z")

</div>

In Kibana 4 I had simple bar charts that showed on the X-Axis the time and on the Y-Axis I had a Split Bar, Sub Aggreation Terms, Field Hostname.raw and then it showed me the Top5 according to my saved search.

In Kibana 5 this doesn't work anymore. The setup is now:  
Sub Aggregation: Terms  
Field: Hostname: raw  
Order by: metric Count  
Order: Descending: 5

But it doesn't split the bar up into the hostnames but shows only bars with a count which seems to be aggregated over the top 5 hostnames I guess. When I enable aggregation I get no results, with disabled aggregation I get the bars with the count.  
The only way I see to get the bars back like in Kibana 4 is using now filters and add a filter by hand for each and every host. But this also means that I have to change my visualizations each time I add a host to my environment which is cumbersome.

How do I get the behavior from Kibana 4 back?

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [December 1, 2016, 6:29pm UTC](https://discuss.elastic.co/t/kibana-5-terms-and-aggregations/67744/2 "2016-12-01T18:29:43Z")

</div>

Hi Niels,

Would you mind sharing a screenshot of the Kibana 4 visualization (including the buckets you have set up) and a screenshot of how it looks in Kibana 5? This will help me understand what you're looking for vs what you're getting in 5.

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![nielsk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nielsk/32/7460_2.png) [@nielsk](https://discuss.elastic.co/u/nielsk)\
**Post date:** [December 2, 2016, 8:47am UTC](https://discuss.elastic.co/t/kibana-5-terms-and-aggregations/67744/3 "2016-12-02T08:47:45Z")

</div>

I don't have a kibana 4-board anymore but I can show you a result of what I am going for:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/cf5956be7c7c7f082e0136182818b60f45f88461.png)

The count is the number of error messages coming in, each color is a different server. In Kibana 5 I have to realize that via a filters-sub-bucket.  
In Kibana 4, I could use a Term-sub-bucket, with Field hostname.raw and let it show the Top 5.

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [December 3, 2016, 1:55am UTC](https://discuss.elastic.co/t/kibana-5-terms-and-aggregations/67744/4 "2016-12-03T01:55:37Z")

</div>

Maybe there is something about your mapping that is making Kibana think that it can't use your `hostname.raw` field. Can you share the details of that field?

I'm thinking it might have something to do with: [https://github.com/elastic/elasticsearch/issues/21952](https://github.com/elastic/elasticsearch/issues/21952)

---

<div class="post-metadata">

**Author:** ![nielsk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nielsk/32/7460_2.png) [@nielsk](https://discuss.elastic.co/u/nielsk)\
**Post date:** [December 5, 2016, 7:10am UTC](https://discuss.elastic.co/t/kibana-5-terms-and-aggregations/67744/5 "2016-12-05T07:10:57Z")

</div>

If I understand it correctly I am running into exactly this bug 😩  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2017, 7:11am UTC](https://discuss.elastic.co/t/kibana-5-terms-and-aggregations/67744/6 "2017-01-02T07:11:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
