# Kibana Filter Query

**URL:** <https://discuss.elastic.co/t/kibana-filter-query/145641>\
**Category:** Kibana\
**Created:** [August 23, 2018, 4:12am UTC](https://discuss.elastic.co/t/kibana-filter-query/145641 "2018-08-23T04:12:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ggajanan](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@ggajanan](https://discuss.elastic.co/u/ggajanan)\
**Post date:** [August 23, 2018, 4:12am UTC](https://discuss.elastic.co/t/kibana-filter-query/145641/1 "2018-08-23T04:12:27Z")

</div>

Hi,

I want to create a query filter for the following SQL query in Kibana (6.3.2)

```
SELECT requestuid
FROM blue-account-2018.08
group by requestuid
having count(requestuid) = 1

```

where,  
blue-account-2018.08 = index name  
requestuid = String data type field

Can somebody help, please?

Thank you!

DSL query executed on ES

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [August 23, 2018, 3:38pm UTC](https://discuss.elastic.co/t/kibana-filter-query/145641/2 "2018-08-23T15:38:35Z")

</div>

I'm getting an exception when I try using HAVING, and not a very useful one: `[search_phase_execution_exception]`. It's possible that it doesn't support HAVING. My SQL is super rusty, but I would expect `WHERE COUNT(requestuid) = 1` to be basically the same query, but that doesn't work... it doesn't cause an exception, but it also doesn't filter any of the results.

Are you also getting an exception or is something else happening with that query?

---

<div class="post-metadata">

**Author:** ![Andrei\_Stefan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrei_stefan/32/47533_2.png) [@Andrei\_Stefan](https://discuss.elastic.co/u/Andrei_Stefan)\
**Post date:** [August 23, 2018, 5:00pm UTC](https://discuss.elastic.co/t/kibana-filter-query/145641/3 "2018-08-23T17:00:59Z")

</div>

@ggajanan additionally to @Joe_Fleming's question, can you also mention how you are running that query and, if possible, include the complete request?  
Thanks

---

<div class="post-metadata">

**Author:** ![Andrei\_Stefan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrei_stefan/32/47533_2.png) [@Andrei\_Stefan](https://discuss.elastic.co/u/Andrei_Stefan)\
**Post date:** [August 23, 2018, 5:10pm UTC](https://discuss.elastic.co/t/kibana-filter-query/145641/4 "2018-08-23T17:10:44Z")

</div>

The only thing that comes to mind that won't work with the query you provided as is, is the escaping part. The query should be:

```auto
POST _xpack/sql?format=txt
{
  "query": "SELECT requestuid FROM \"blue-account-2018.08\" group by requestuid having count(requestuid) = 1"
}

```

---

<div class="post-metadata">

**Author:** ![ggajanan](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@ggajanan](https://discuss.elastic.co/u/ggajanan)\
**Post date:** [August 26, 2018, 6:29pm UTC](https://discuss.elastic.co/t/kibana-filter-query/145641/5 "2018-08-26T18:29:20Z")

</div>

Perfect! Thank you so much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2018, 6:29pm UTC](https://discuss.elastic.co/t/kibana-filter-query/145641/6 "2018-09-23T18:29:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
