# \[Kibana\]: Nested child fields can not be visualized in discovery and be used like a filter aggregation

**URL:** <https://discuss.elastic.co/t/kibana-nested-child-fields-can-not-be-visualized-in-discovery-and-be-used-like-a-filter-aggregation/218739>\
**Category:** Kibana\
**Created:** [February 11, 2020, 9:23am UTC](https://discuss.elastic.co/t/kibana-nested-child-fields-can-not-be-visualized-in-discovery-and-be-used-like-a-filter-aggregation/218739 "2020-02-11T09:23:02Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![AlekssM](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@AlekssM](https://discuss.elastic.co/u/AlekssM)\
**Post date:** [February 11, 2020, 9:23am UTC](https://discuss.elastic.co/t/kibana-nested-child-fields-can-not-be-visualized-in-discovery-and-be-used-like-a-filter-aggregation/218739/1 "2020-02-11T09:23:02Z")

</div>

Hello,

Could you please give me an advice on how to be able to visualize and count field which is in the child doc and it is type: nested.  
I have seen several questions since '15 but no workarounds for this specific issue.

However, in the Kibana console i managed to get the proper count but when i put it like a raw query int the discovery section it gives a different and not accurate count.

Following query:

GET my\_index/\_count  
{

```
"query" : {
    "nested": {
        "path": "field1",
        "query": {
            "bool": {
                "must": [
                    {
                        "exists": {
                            "field": "field1.field2"
                        }
                    }
                ]
            }
        }
    }
}

```

}

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [February 12, 2020, 4:05pm UTC](https://discuss.elastic.co/t/kibana-nested-child-fields-can-not-be-visualized-in-discovery-and-be-used-like-a-filter-aggregation/218739/2 "2020-02-12T16:05:57Z")

</div>

The KQL query language has recently added support for nested fields: [https://www.elastic.co/guide/en/kibana/7.6/kuery-query.html#kuery-query-nested-field](https://www.elastic.co/guide/en/kibana/7.6/kuery-query.html#kuery-query-nested-field)

Those should be easier to use than raw queries

---

<div class="post-metadata">

**Author:** ![AlekssM](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@AlekssM](https://discuss.elastic.co/u/AlekssM)\
**Post date:** [February 13, 2020, 11:09am UTC](https://discuss.elastic.co/t/kibana-nested-child-fields-can-not-be-visualized-in-discovery-and-be-used-like-a-filter-aggregation/218739/3 "2020-02-13T11:09:23Z")

</div>

Thank you for your answer, but since my field with type nested is in the child doc its seems the KQL queries don't work either. This is a portion of my predefined mapping

```
   "field1" : {
				"type" : "nested",
				"properties" : {
					"field2" : {"type" : "keyword"},
					"field3" : {"type" : "keyword"},
					"field4" : {
						"type": "nested",
						"properties" : {
							"field5" : {"type" : "keyword"},
							"timestamp" : {"type" : "date"}
						}
					}
				}
			}

```

I want to check how many docs have the field: "field1.field2"(ex. _exists_:field1.field2). Can you suggest me a solution query, or maybe I need to put the include\_in\_parent/root parameter in the mapping just below the type:nested parameter so i can perform _exists_ or KQL queries?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [February 13, 2020, 11:17am UTC](https://discuss.elastic.co/t/kibana-nested-child-fields-can-not-be-visualized-in-discovery-and-be-used-like-a-filter-aggregation/218739/4 "2020-02-13T11:17:51Z")

</div>

If it's possible for you, then the easiest way now is to copy the fields into a non-nested type via `copy_to` so Kibana can work with it. Only KQL supports some situations around nested objects at the moment, so "unnesting" is required to create e.g. visualizations.

---

<div class="post-metadata">

**Author:** ![AlekssM](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@AlekssM](https://discuss.elastic.co/u/AlekssM)\
**Post date:** [February 13, 2020, 1:00pm UTC](https://discuss.elastic.co/t/kibana-nested-child-fields-can-not-be-visualized-in-discovery-and-be-used-like-a-filter-aggregation/218739/5 "2020-02-13T13:00:56Z")

</div>

My doc mapping, in regards to "field1", must be nested because one particular document can have several "field1" objects, so "unnesting" does not really work for me.  
So if there is not Kibana support for querying and visualizing nested child fields, can i make scripted field or my own custom filter in order to visualize (or in extend to filter with Python and than somehow visualize in Kibana)? This particular visualization is of great importance for me.  
Thank you for taking the time answering my questions! I really appreciate it!

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [February 13, 2020, 1:08pm UTC](https://discuss.elastic.co/t/kibana-nested-child-fields-can-not-be-visualized-in-discovery-and-be-used-like-a-filter-aggregation/218739/6 "2020-02-13T13:08:19Z")

</div>

`copy_to` will also work if there are multiple values - a field in Elasticsearch can always also contain an array of its type. The things you loose is the association between the individual fields of the nested objects -

```auto
{ nested: [{ field1: 'a', field2:'b' }, { field1: 'c', field2:'d' }] }

```

would become

```auto
{ nested.field1: ['a', 'c'], nested.field2: ['b', 'd']}

```

So Kibana wouldn't know anymore whether `'a'` occured together with `'b'` or `'d'`. But for simple exist queries and also quite some visualizations this wouldn't matter.

If this is important for your visualization, another approach is to split up the documents and create a separate top level document for each nested object.

```auto
{ nested: [{ field1: 'a', field2:'b' }, { field1: 'c', field2:'d' }], field3: 1234 }

```

would become these two documents:

```auto
{ nested: { field1: 'a', field2:'b' }, field3: 1234 }
{ nested: { field1: 'c', field2:'d' }, field3: 1234 }

```

---

<div class="post-metadata">

**Author:** ![AlekssM](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@AlekssM](https://discuss.elastic.co/u/AlekssM)\
**Post date:** [February 14, 2020, 12:30pm UTC](https://discuss.elastic.co/t/kibana-nested-child-fields-can-not-be-visualized-in-discovery-and-be-used-like-a-filter-aggregation/218739/7 "2020-02-14T12:30:56Z")

</div>

Thank you very much this worked for me! I also tried, just to include "include\_in\_parent:true" parameter beneath the nested child field, and I was able to apply exists aggregation on it 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2020, 12:30pm UTC](https://discuss.elastic.co/t/kibana-nested-child-fields-can-not-be-visualized-in-discovery-and-be-used-like-a-filter-aggregation/218739/8 "2020-03-13T12:30:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
