# Kibana (ELK)- create complex query in Kibana

**URL:** <https://discuss.elastic.co/t/kibana-elk-create-complex-query-in-kibana/163681>\
**Category:** Kibana\
**Created:** [January 10, 2019, 9:06am UTC](https://discuss.elastic.co/t/kibana-elk-create-complex-query-in-kibana/163681 "2019-01-10T09:06:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![HilaS](https://avatars.discourse-cdn.com/v4/letter/h/8baadc/32.png) [@HilaS](https://discuss.elastic.co/u/HilaS)\
**Post date:** [January 10, 2019, 9:06am UTC](https://discuss.elastic.co/t/kibana-elk-create-complex-query-in-kibana/163681/1 "2019-01-10T09:06:25Z")

</div>

I want to create a vertical bar that while show me for each file, the last status of the file. I have files that can be in status: Start, Completed, Failed. I file that is in Failed status will be re-run and probably will move to a different status when the time passes. I want to create a query such as: select Distinct FileName, status from log

but when I'm looking on the diagram, I see that for 24 hours, the same files are in Start and Completed. And for a period of time I only want the last status of the file.

 ![kibana](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb364df606d42ad98e88fbc497ef7f233c9fa3af.png)

in my messages I have fileName and Status of the file, for example:  
hila1.txt received  
hila2.txt received  
hila2.txt started  
hila3.txt received  
hila3.txt started  
hila3.txt completed  
hila4.txt received  
hila4.txt started  
hila4.txt failed.

but, file hila4.txt can re run again and we can get new messages:  
hila4.txt received  
hila4.txt started  
hila4.txt completed

I want to create a View (Diagram) that will show me for the last status of  
each file how many files in each status.  
For this example:  
received - 1  
started - 1  
completed - 2  
failed - 0 (because hila4.txt had run again and succeeded).

can it be done?  
Could someone please help me?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2019, 9:06am UTC](https://discuss.elastic.co/t/kibana-elk-create-complex-query-in-kibana/163681/2 "2019-02-07T09:06:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
