# Kibana Greater Than or Equal To

**URL:** <https://discuss.elastic.co/t/kibana-greater-than-or-equal-to/140932>\
**Category:** Kibana\
**Created:** [July 20, 2018, 3:29pm UTC](https://discuss.elastic.co/t/kibana-greater-than-or-equal-to/140932 "2018-07-20T15:29:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_McAfee1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_mcafee1/32/47236_2.png) [@John\_McAfee1](https://discuss.elastic.co/u/John_McAfee1)\
**Post date:** [July 20, 2018, 3:29pm UTC](https://discuss.elastic.co/t/kibana-greater-than-or-equal-to/140932/1 "2018-07-20T15:29:41Z")

</div>

Good Morning!  
I need to perform a Range query in Kibana, but have run into a problem. From the Discover tab, I need to perform this query (count(sourcename:"name") \>= 1 )to get back a list of documents. I have not figured how to use the range syntax of field:[\* TO 100] to work for my query because I need the count function first. Is this query from the Discover tab and if so, I would appreciate some guidance.

Thank you!!

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [July 24, 2018, 10:54pm UTC](https://discuss.elastic.co/t/kibana-greater-than-or-equal-to/140932/2 "2018-07-24T22:54:55Z")

</div>

Could you provide an example of one of your documents? I'm not understanding how you can have a count where sourcename is name for a single document, unless sourcename is an array or something.

---

<div class="post-metadata">

**Author:** ![John\_McAfee1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_mcafee1/32/47236_2.png) [@John\_McAfee1](https://discuss.elastic.co/u/John_McAfee1)\
**Post date:** [July 26, 2018, 12:17am UTC](https://discuss.elastic.co/t/kibana-greater-than-or-equal-to/140932/3 "2018-07-26T00:17:09Z")

</div>

Hello Lukas!

Thank you for your reply. Sorry, that I did not mention that. Yes, sourcename is an array. I will get an example if you still need it?

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [July 26, 2018, 10:21pm UTC](https://discuss.elastic.co/t/kibana-greater-than-or-equal-to/140932/4 "2018-07-26T22:21:18Z")

</div>

Which version of Kibana are you using? If you're using something prior to 6.3, you'll have to use a [script query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-script-query.html) to accomplish this.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [July 26, 2018, 10:51pm UTC](https://discuss.elastic.co/t/kibana-greater-than-or-equal-to/140932/5 "2018-07-26T22:51:13Z")

</div>

So it'd be something like this you'd paste into the query bar:

```auto
{
    "script" : {
        "script" : {
            "source": "for (int i = 0; i < doc['sourcename.keyword'].length; ++i) { if (doc['sourcename.keyword'][i].equals('name')) { return true; } } return false;",
            "lang": "painless"
         }
    }
}

```

---

<div class="post-metadata">

**Author:** ![John\_McAfee1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_mcafee1/32/47236_2.png) [@John\_McAfee1](https://discuss.elastic.co/u/John_McAfee1)\
**Post date:** [July 27, 2018, 3:36am UTC](https://discuss.elastic.co/t/kibana-greater-than-or-equal-to/140932/6 "2018-07-27T03:36:19Z")

</div>

Hello Lukas:

Thank you very much for your response! At the moment, we are using 6.2.2. But will be upgrading to 6.3.2 next week. Is the syntax in 6.3 very much different?

Thank you,

- John

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [July 27, 2018, 4:20pm UTC](https://discuss.elastic.co/t/kibana-greater-than-or-equal-to/140932/7 "2018-07-27T16:20:33Z")

</div>

You can do the same thing in 6.3.x, but we've added a few features to make this sort of thing easier in 6.3+.

You can create a scripted field (in your index pattern settings), and set the script to something like this:

```auto
int total = 0;
for (int i = 0; i < doc['sourcename.keyword'].length; ++i) {
  if (doc['sourcename.keyword'][i].equals('name')) total++;
}
return total;

```

Then, in 6.3+, there is an Options link in the query bar, which has a toggle to enable advanced query features. If you enable this, you can use scripted fields in your query. For example, if I had named the scripted field `sourcename_name`, then I could simply do a query in the query bar like this: `sourcename_name >= 1`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2018, 4:20pm UTC](https://discuss.elastic.co/t/kibana-greater-than-or-equal-to/140932/8 "2018-08-24T16:20:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
