# \[Kibana Table Visualisation\] Column: count how many times a field has a specific value

**URL:** <https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294>\
**Category:** Kibana\
**Created:** [April 9, 2018, 9:47am UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294 "2018-04-09T09:47:16Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![schmittberger](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@schmittberger](https://discuss.elastic.co/u/schmittberger)\
**Post date:** [April 9, 2018, 9:47am UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294/1 "2018-04-09T09:47:16Z")

</div>

Hello, I am trying to create a table visualisation that shows statistics about REST-WS calls. Now I am stuck with showing a column where the number of calls that ended up in a specific result code (let's say 404) is shown.  
I think the solution includes the json input field. But here is my question:  
How can I manipulate if a document is counted or not for the count metric using the json input.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/f/cfb057fc9f1b648158ca1e8d7fbcf667071af800.jpg)

Also, is there a way to cast the values from string to number and do a range comparisson like "\>= 400 AND \< 500"?

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [April 9, 2018, 4:42pm UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294/2 "2018-04-09T16:42:15Z")

</div>

Tagging @timroes here. Thanks Tim.

Cheers,  
Bhavya

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [April 9, 2018, 5:02pm UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294/3 "2018-04-09T17:02:53Z")

</div>

Hi,

unfortunately that's not possible currently. You cannot create a separate filter for a specific metric only for the visualization as a whole, so I fear you cannot show this in the same table.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![schmittberger](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@schmittberger](https://discuss.elastic.co/u/schmittberger)\
**Post date:** [April 9, 2018, 5:56pm UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294/4 "2018-04-09T17:56:34Z")

</div>

OK, so I added a subbucket on the response code an get one table for each response code that exists in the data. Is there a way to (cast to a number) and combine all 2xx response codes into one table (same for 3xx, 4xx and 5xx of course)?

Thanks

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [April 10, 2018, 4:02pm UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294/5 "2018-04-10T16:02:27Z")

</div>

I think if the fields contains a response code you should rather index it properly as a numeric field. That way you could do all numeric operations, like doing a range aggregation on it to get everything between 200-299, etc. in one bucket.

If it's a string field, you still can work around it in that case, by using a filters aggregations, and just create the filters like: `response:2*`, `response:3*`, etc. to get the corresponding response code "ranges".

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![schmittberger](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@schmittberger](https://discuss.elastic.co/u/schmittberger)\
**Post date:** [April 11, 2018, 10:08am UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294/6 "2018-04-11T10:08:38Z")

</div>

Thank you for your input. I managed to change the status field to be an integer and did a range agg. Everything is fine except for the title of the tables which somehow doesn't show the range from and to values. Is this a (known) bug or did I miss something?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/94b297078ed49d916fde27b2e73765ca7a5ac1b5.jpg)

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [April 11, 2018, 10:21am UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294/7 "2018-04-11T10:21:23Z")

</div>

That should of course show. Could you tell me which version you are using?

---

<div class="post-metadata">

**Author:** ![schmittberger](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@schmittberger](https://discuss.elastic.co/u/schmittberger)\
**Post date:** [April 11, 2018, 10:22am UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294/8 "2018-04-11T10:22:30Z")

</div>

6.2.2 - both elasticsearch and kibana

---

<div class="post-metadata">

**Author:** ![schmittberger](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@schmittberger](https://discuss.elastic.co/u/schmittberger)\
**Post date:** [April 19, 2018, 9:01am UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294/9 "2018-04-19T09:01:01Z")

</div>

@timroes: Any news on this? Fix / Workaround?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2018, 9:01am UTC](https://discuss.elastic.co/t/kibana-table-visualisation-column-count-how-many-times-a-field-has-a-specific-value/127294/10 "2018-05-17T09:01:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
