# Kibana - discover - group by exception.ClassName

**URL:** <https://discuss.elastic.co/t/kibana-discover-group-by-exception-classname/192617>\
**Category:** Kibana\
**Created:** [July 29, 2019, 7:15am UTC](https://discuss.elastic.co/t/kibana-discover-group-by-exception-classname/192617 "2019-07-29T07:15:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jross](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jross/32/51091_2.png) [@jross](https://discuss.elastic.co/u/jross)\
**Post date:** [July 29, 2019, 7:15am UTC](https://discuss.elastic.co/t/kibana-discover-group-by-exception-classname/192617/1 "2019-07-29T07:15:03Z")

</div>

Hi, I would like to visualize the logs with every 'exception.ClassName' different,  
I mean, if I have 30 logs with the same 'exception.ClassName', it should appear one time, because otherwise, it's very difficult to manage the differents errors.

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/4/b/4b4617b84bb0f1e48c57c88b7763b67ab4b58696.png)

I can filter properly, but I have many errors with the same name and I don't know how can I group it.

Many thanks in advance.

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [July 29, 2019, 5:59pm UTC](https://discuss.elastic.co/t/kibana-discover-group-by-exception-classname/192617/2 "2019-07-29T17:59:40Z")

</div>

This can be accomplished by using a Unique Count aggregation in the Metrics of a visualization. [https://www.elastic.co/guide/en/kibana/7.2/xy-chart.html](https://www.elastic.co/guide/en/kibana/7.2/xy-chart.html)

---

<div class="post-metadata">

**Author:** ![jross](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jross/32/51091_2.png) [@jross](https://discuss.elastic.co/u/jross)\
**Post date:** [August 14, 2019, 8:00am UTC](https://discuss.elastic.co/t/kibana-discover-group-by-exception-classname/192617/3 "2019-08-14T08:00:44Z")

</div>

> [@nickpeihl](#):
>
> Unique Count aggregation

thanks for your reply,

using 'count' aggregation, and filter by level: error, I can see just the number of distinct errors,  
but I can see the error details, I mean, I have 2 differents errors, but I would like to know more details about the type of error. Is it possible?  
Many thanks in advance.

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e25e35d26e8c27b2a9a659ac860876ea43a28ed7.png)

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [August 14, 2019, 3:37pm UTC](https://discuss.elastic.co/t/kibana-discover-group-by-exception-classname/192617/4 "2019-08-14T15:37:37Z")

</div>

Perhaps you can use a Data Table visualization similar to [this demo](https://demo.elastic.co/app/kibana#/visualize/edit/a0340090-1389-11e8-8c94-a3d8d0cfd62b?_g=(refreshInterval%3A(pause%3A!t%2Cvalue%3A0)%2Ctime%3A(from%3Anow-4h%2Cto%3Anow))).

 ![Screenshot_2019-08-14%20Users%20List%20%5BAzure%20Monitor%5D%5BActivity%20Log%5D%20-%20Kibana(2)](https://us1.discourse-cdn.com/elastic/original/3X/d/f/df24dfe6e9b552102669fa7f6fe0de4245d4e10c.png)

This demo uses sub-buckets to group by email, first name, and last name. It provides a unique count of IP addresses and a total count of all activity.

I suspect you could do something similar with a Terms Aggregation on the `exception.ClassName` field and adding sub-bucket Terms aggregations for other fields you want to know about.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 11, 2019, 3:37pm UTC](https://discuss.elastic.co/t/kibana-discover-group-by-exception-classname/192617/5 "2019-09-11T15:37:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
