# Kibana Saved Search

**URL:** <https://discuss.elastic.co/t/kibana-saved-search/89395>\
**Category:** Kibana\
**Created:** [June 14, 2017, 2:22pm UTC](https://discuss.elastic.co/t/kibana-saved-search/89395 "2017-06-14T14:22:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![c.pentasuglia](https://avatars.discourse-cdn.com/v4/letter/c/5daacb/32.png) [@c.pentasuglia](https://discuss.elastic.co/u/c.pentasuglia)\
**Post date:** [June 14, 2017, 2:22pm UTC](https://discuss.elastic.co/t/kibana-saved-search/89395/1 "2017-06-14T14:22:28Z")

</div>

Trying to come up with a bit of a complex saved search here....

Suppose I store events into ELK, and the event has a success and failure field on it. In some cases, failures are reported prematurely, and then a success event is logged for that same event. These things are tied together based on an eventID field.

So how might I go about saying:

Give me all events where the status field is FAILURE, and where there does not exist another event with the same eventID that has it's status field set to SUCCESS.

Any idea?  
Thanks!

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [June 14, 2017, 5:06pm UTC](https://discuss.elastic.co/t/kibana-saved-search/89395/2 "2017-06-14T17:06:03Z")

</div>

I'm sorry, but unless you are removing the "failure" reports when the "success" report is indexed I'm pretty confident that there isn't a way to get the correct results in a saved search.

---

<div class="post-metadata">

**Author:** ![c.pentasuglia](https://avatars.discourse-cdn.com/v4/letter/c/5daacb/32.png) [@c.pentasuglia](https://discuss.elastic.co/u/c.pentasuglia)\
**Post date:** [June 14, 2017, 6:43pm UTC](https://discuss.elastic.co/t/kibana-saved-search/89395/3 "2017-06-14T18:43:02Z")

</div>

I see. That's what I was thinking. The query is would very complex if event possible. I wonder if I can perform a query within logstash and handle this case.

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [June 14, 2017, 7:30pm UTC](https://discuss.elastic.co/t/kibana-saved-search/89395/4 "2017-06-14T19:30:06Z")

</div>

Perhaps you could just derive the `id` for these documents from the `eventID` so subsequent index requests will override the previous document (since they would have the same `eventID`, and therefore `id`)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2017, 7:30pm UTC](https://discuss.elastic.co/t/kibana-saved-search/89395/5 "2017-07-12T19:30:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
