# \[Kibana Enhanced Table\] Request for Docs and Tutorials for Scripting Language

**URL:** <https://discuss.elastic.co/t/kibana-enhanced-table-request-for-docs-and-tutorials-for-scripting-language/186615>\
**Category:** Kibana\
**Created:** [June 20, 2019, 7:27am UTC](https://discuss.elastic.co/t/kibana-enhanced-table-request-for-docs-and-tutorials-for-scripting-language/186615 "2019-06-20T07:27:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zany](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zany/32/50113_2.png) [@Zany](https://discuss.elastic.co/u/Zany)\
**Post date:** [June 20, 2019, 7:27am UTC](https://discuss.elastic.co/t/kibana-enhanced-table-request-for-docs-and-tutorials-for-scripting-language/186615/1 "2019-06-20T07:27:32Z")

</div>

First of all, I would like to thank @fbaligand for creating the awesome [Kibana Enhanced Table](https://github.com/fbaligand/kibana-enhanced-table) plugin, it is really useful.

I understand that I can use `col[n]` to **reference existing columns in the data table** to derive a new column. I am able to get this working fine.  
 ![Computed%20Column%201](https://us1.discourse-cdn.com/elastic/original/3X/8/2/82028b08895cc7b21478c797714ce3df8ad26604.png)

I am trying to **reference a field in my index pattern** to derive a new column. However, it does not work because my script is not correct. As such, I would like to request for tutorials on using the expr-eval syntax in Kibana so that I can write the correct scripts and get things working. Thanks.

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [June 21, 2019, 9:39am UTC](https://discuss.elastic.co/t/kibana-enhanced-table-request-for-docs-and-tutorials-for-scripting-language/186615/2 "2019-06-21T09:39:30Z")

</div>

Hi,

First of all, thanks for your interest to kibana enhanced-table plugin!  
Happy to see you enjoy it 🙂

Then, to answer to your question,

- firstly, don't forget that Enhanced Table (like Data Table) aims to display aggregations, not documents.
- and so, you can't directly access document fields like that in a computed column formula
- but you can display documents and add computed-columns, using some tips :
  - in "Data" tab, in "Buckets" section, click on 'Split Cols', and create a 'Terms' aggregation based on "\_id" field (or any unique field)
  - then, add a 'Terms' bucket (size=1) or 'Top Hits' metric for each field you want to use in computed column formula. For example a 'Terms' aggregation based on "in\_authentication\_success" field.
  - then, in "Options" tab, add a new computed column, and reference each column you need for your computed column using `col[1]` or `col1`.  
For example : `col1 == "Y" ? 1 : 0`
  - finally, using "Hidden columns" setting, hide every column you don't want to display. For example "\_id" and "in\_authentication\_success" columns.

A last thing: if you want some reference documentation about what you can do in a computed column formula, click on "expr-eval" link above "Formula" setting. It provides full documentation about what you can do.

Hope it helps you

---

<div class="post-metadata">

**Author:** ![Zany](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zany/32/50113_2.png) [@Zany](https://discuss.elastic.co/u/Zany)\
**Post date:** [June 25, 2019, 6:55am UTC](https://discuss.elastic.co/t/kibana-enhanced-table-request-for-docs-and-tutorials-for-scripting-language/186615/3 "2019-06-25T06:55:59Z")

</div>

Thanks for the clarifications and the workaround solution.

This is the setup of 4 metrics, 1 bucket and 1 calculated formula before applying the solution.

 ![Data%20Config](https://us1.discourse-cdn.com/elastic/original/3X/e/a/ea58f61c7818bf947bbfa8e9092750ede4e172a9.png)

> [@fbaligand](#):
>
> but you can display documents and add computed-columns, using some tips :
> 
> - in "Data" tab, in "Buckets" section, click on 'Split Cols', and create a 'Terms' aggregation based on "\_id" field (or any unique field)
> - then, add a 'Terms' bucket (size=1) or 'Top Hits' metric for each field you want to use in computed column formula. For example a 'Terms' aggregation based on "in\_authentication\_success" field.
> - then, in "Options" tab, add a new computed column, and reference each column you need for your computed column using `col[1]` or `col1` .  
> For example : `col1 == "Y" ? 1 : 0`

Many repeating columns appeared in my table after following Step 1 and 2 of the instruction. I could not proceed with Step 3.

---

<div class="post-metadata">

**Author:** ![Zany](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zany/32/50113_2.png) [@Zany](https://discuss.elastic.co/u/Zany)\
**Post date:** [June 25, 2019, 7:53am UTC](https://discuss.elastic.co/t/kibana-enhanced-table-request-for-docs-and-tutorials-for-scripting-language/186615/4 "2019-06-25T07:53:41Z")

</div>

I decided to try using the Scripted Fields, and managed to calculate the Authentication Rate. Looks like I have a lot more to learn. Thanks for the support.

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [June 25, 2019, 8:21am UTC](https://discuss.elastic.co/t/kibana-enhanced-table-request-for-docs-and-tutorials-for-scripting-language/186615/5 "2019-06-25T08:21:06Z")

</div>

Through your 2 last comments, I understand that you don’t want a table line per document, but a table line per aggregation.  
That’s why my tip does not solve your need.

If you want some computed field based on document fields, and then compute an aggregation on it to display on a table (or any visualization), then the Kibana scripted field is indeed the good choice!

---

<div class="post-metadata">

**Author:** ![Zany](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zany/32/50113_2.png) [@Zany](https://discuss.elastic.co/u/Zany)\
**Post date:** [June 25, 2019, 9:56am UTC](https://discuss.elastic.co/t/kibana-enhanced-table-request-for-docs-and-tutorials-for-scripting-language/186615/6 "2019-06-25T09:56:59Z")

</div>

Pardon me if I didn't explain my requirements clearly. Thanks again for clarifying and confirmation on using Kibana scripted field. Cheers! 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2019, 9:57am UTC](https://discuss.elastic.co/t/kibana-enhanced-table-request-for-docs-and-tutorials-for-scripting-language/186615/7 "2019-07-23T09:57:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
