# Kibana bar chart doesn't work for filters aggregation

**URL:** <https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633>\
**Category:** Kibana\
**Tags:** vega\
**Created:** [February 8, 2021, 4:02pm UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633 "2021-02-08T16:02:50Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![elster](https://avatars.discourse-cdn.com/v4/letter/e/dbc845/32.png) [@elster](https://discuss.elastic.co/u/elster)\
**Post date:** [February 8, 2021, 4:02pm UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/1 "2021-02-08T16:02:51Z")

</div>

Dear experts,

I created several Vega (lite) barcharts using this code:

```auto
{
  $schema: https://vega.github.io/schema/vega-lite/v2.json
  title: Login Method Distribution
  data: {
    url: {
}
    format: {property: "aggregations.nested_app.saml_message.loginmethods.buckets"}
  }
  mark: bar
  encoding: {
    y: {
      field: key
      type: nominal
      sort: -x
      axis: {title: "Login Method"}
    }
    x: {
      field: doc_count
      type: quantitative
      axis: {title: "Number of logins last 7 days"}
    }
  }
}

```

This works fine with buckets resulting from terms aggregation:

```auto
          "buckets" : [
            {
              "key" : "https://myvideo.com",
              "doc_count" : 91652,
            {
              "key" : "https://myaudio.com",
              "doc_count" : 14446
            }
            }
          ]

```

but not with buckets resulting from filters aggregation:

```auto
"buckets" : {
            "CERTIFICATE" : {
              "doc_count" : 167523
            },
            "MSCERTIFICATE" : {
              "doc_count" : 4865
            }
          }

```

Any idea how to change the encoding (or other) sections to get this accomplished?

Thanks and br,  
Elmar

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [February 8, 2021, 8:17pm UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/2 "2021-02-08T20:17:32Z")

</div>

You are using named filters instead of [anonymous filters](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-filters-aggregation.html#_anonymous_filters). Anonymous filters will return the same format as the Terms aggregation.

---

<div class="post-metadata">

**Author:** ![elster](https://avatars.discourse-cdn.com/v4/letter/e/dbc845/32.png) [@elster](https://discuss.elastic.co/u/elster)\
**Post date:** [February 8, 2021, 9:12pm UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/3 "2021-02-08T21:12:05Z")

</div>

Hey Wylie,

Thanks for your valuable hint!

I was thinking about this option already, however in that case I get the values in the format below and I have no idea how to map them to the related keys. The bar (or even better a pie) chart should show the counts of 'CERTIFICATE', 'MSCERTIFICATE', etc...

```auto
          "buckets" : [
            {
              "doc_count" : 1135
            },
            {
              "doc_count" : 1136
            }
          ]

```

Meanwhile I figured out that if filters aren't anonymous, I can access the doc\_count field this way: MSCERTIFICATE.doc\_count but then I still have no idea how to 'paint' the bar chart properly so that all options are displayed and not just one:

```auto
    y: {
      field: MSCERTIFICATE
      type: nominal
      sort: -x
      axis: {title: "Login Method"}
    }
    x: {
      field: MSCERTIFICATE.doc_count
      type: quantitative
      axis: {title: "Number of logins last 7 days"}
    }

```

I would need sth like

```auto
    y1: {
      field: MSCERTIFICATE
      type: nominal
      sort: -x
      axis: {title: "Login Method"}
    }
    x1: {
      field: MSCERTIFICATE.doc_count
      type: quantitative
      axis: {title: "Number of logins last 7 days"}
    }
    y2: {
      field: CERTIFICATE
      type: nominal
      sort: -x
      axis: {title: "Login Method"}
    }
    x2: {
      field: CERTIFICATE.doc_count
      type: quantitative
      axis: {title: "Number of logins last 7 days"}
    }

```

Hope you can help me out here,  
Elmar

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [February 8, 2021, 9:18pm UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/4 "2021-02-08T21:18:18Z")

</div>

> [@elster](#):
>
> ```auto
> "buckets" : {
> "CERTIFICATE" : {
> "doc_count" : 167523
> },
> "MSCERTIFICATE" : {
> "doc_count" : 4865
> }
> }
> 
> ```

` format: {property: "aggregations.nested_app.saml_message.loginmethods.buckets"}`

In your first sample buckets is an array. In the example above it is not. So you should be getting an error when trying to format it I think.

How or why I don't know, just pointing that part out.

---

<div class="post-metadata">

**Author:** ![elster](https://avatars.discourse-cdn.com/v4/letter/e/dbc845/32.png) [@elster](https://discuss.elastic.co/u/elster)\
**Post date:** [February 8, 2021, 9:21pm UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/5 "2021-02-08T21:21:19Z")

</div>

Yes, thx, that's exactly the problem! This is how filters aggregation works. The question is how to modify my Vega configuration to make the bar chart work anyway!

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [February 8, 2021, 9:42pm UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/6 "2021-02-08T21:42:48Z")

</div>

Did you try `buckets.CERTIFICATE.doc_count` and `buckets.MSCERTIFICATE.doc_count`?

Not sure what your data looks like. If that doesn't work can you paste in the `response` from the query?

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [February 8, 2021, 9:42pm UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/7 "2021-02-08T21:42:48Z")

</div>

I see your point. Using named filters is probably best, and then you can use the [fold transform](https://vega.github.io/vega-lite/docs/fold.html) in Vega-Lite. Here is an example:

```auto
{
  "$schema": "https://vega.github.io/schema/vega-lite/v4.json",
  "data": {
    "values": [{
      "buckets" : {
        "CERTIFICATE" : {
          "doc_count" : 167523
        },
        "MSCERTIFICATE" : {
          "doc_count" : 4865
        }
      }
    }]
  },
  "transform": [{
    "fold": ["buckets.CERTIFICATE", "buckets.MSCERTIFICATE"]
  }],
  "mark": "bar",
  "encoding": {
    "x": {
      "field": "key",
      "type": "ordinal"
    },
    "y": {
      "field": "value.doc_count",
      "type": "quantitative"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![elster](https://avatars.discourse-cdn.com/v4/letter/e/dbc845/32.png) [@elster](https://discuss.elastic.co/u/elster)\
**Post date:** [February 9, 2021, 7:42pm UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/8 "2021-02-09T19:42:22Z")

</div>

Bäm this works!! Thanks a lot, very appreciated!!

---

<div class="post-metadata">

**Author:** ![grra](https://avatars.discourse-cdn.com/v4/letter/g/a6a055/32.png) [@grra](https://discuss.elastic.co/u/grra)\
**Post date:** [February 10, 2021, 8:37am UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/9 "2021-02-10T08:37:29Z")

</div>

Hi!

I am facing the same problem, in Vega-Lite Editor I can see the examples results. But in Kibana I can only see the x- and y- Axis, with their names `key` and `value.doc_count` but the graph is empty.

Are you maybe familiar with that problem?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [February 10, 2021, 12:39pm UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/10 "2021-02-10T12:39:56Z")

</div>

@grra I would open a new topic with your question and include your [Vega Spec](https://www.elastic.co/guide/en/kibana/current/vega-reference.html#asking-for-help-with-a-vega-spec) if possible.

---

<div class="post-metadata">

**Author:** ![grra](https://avatars.discourse-cdn.com/v4/letter/g/a6a055/32.png) [@grra](https://discuss.elastic.co/u/grra)\
**Post date:** [February 12, 2021, 9:31am UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/11 "2021-02-12T09:31:00Z")

</div>

> [@Vega-Lite bar chart doesn't show anything for filters aggregation](https://discuss.elastic.co/t/vega-lite-bar-chart-doesnt-show-anything-for-filters-aggregation/263882):
>
> Hello, In my Vega-Lit spec I do a query which returns the following response: "aggregations" : { "my-groups" : { "buckets" : { "group-1" : { "doc\_count" : 16958 }, "group-2" : { "doc\_count" : 3248 }, "group-3" : { "doc\_count" : 408 } } } } } I have a Vega-lite barchart like that: { "$schema": "https://vega.github.io/schema/vega-lite/v2.json", "data": { "url": { # Query whic…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2021, 9:31am UTC](https://discuss.elastic.co/t/kibana-bar-chart-doesnt-work-for-filters-aggregation/263633/12 "2021-03-12T09:31:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
