# Kibana Visualaztion Data Table 'Missing' values

**URL:** <https://discuss.elastic.co/t/kibana-visualaztion-data-table-missing-values/155957>\
**Category:** Kibana\
**Created:** [November 8, 2018, 8:40pm UTC](https://discuss.elastic.co/t/kibana-visualaztion-data-table-missing-values/155957 "2018-11-08T20:40:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![uklipse](https://avatars.discourse-cdn.com/v4/letter/u/cdc98d/32.png) [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Post date:** [November 8, 2018, 8:40pm UTC](https://discuss.elastic.co/t/kibana-visualaztion-data-table-missing-values/155957/1 "2018-11-08T20:40:52Z")

</div>

Hi, I'm trying to create a table that shows the breakdown of user with the number of login attempts from a workstation. When I initially ran this, I was seeing a number lower than expected. I checked the Show Missing field and I could see the missing counts but the source workstation now says Missing for each user login. One odd thing is the Missing field is always the highest number for each login attempt. Running a query in Discover shows the correct results.

Any ideas why it's showing this way?

 ![Kibana%20Missing](https://us1.discourse-cdn.com/elastic/original/3X/e/c/eccb2902b75e5639047a5423912f48457080a0c8.png)

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [November 8, 2018, 9:05pm UTC](https://discuss.elastic.co/t/kibana-visualaztion-data-table-missing-values/155957/2 "2018-11-08T21:05:13Z")

</div>

I'd need to see how you're building the aggregation (the stuff in the "Data" tab) to help you out. If you can't share a screenshot, can you at least explain the fields you're dealing with and how you're aggregating them?

---

<div class="post-metadata">

**Author:** ![uklipse](https://avatars.discourse-cdn.com/v4/letter/u/cdc98d/32.png) [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Post date:** [November 8, 2018, 9:21pm UTC](https://discuss.elastic.co/t/kibana-visualaztion-data-table-missing-values/155957/3 "2018-11-08T21:21:08Z")

</div>

Here is the screenshots.

 ![Kibana%20Missing%202](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a532d8cb01bad4f97e95eb199f751bf94be1f658.png)  
 ![Kibana%20Missing%203](https://us1.discourse-cdn.com/elastic/original/3X/1/9/198fa10bfb7bfb37c9669a2d710a48b60fcb1966.png)

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [November 8, 2018, 9:36pm UTC](https://discuss.elastic.co/t/kibana-visualaztion-data-table-missing-values/155957/4 "2018-11-08T21:36:05Z")

</div>

Ok, so you're just splitting on username, and then splitting again on workstation. I'd guess that in your data, you've got records that capture a user's login attempt _without a workstation name_, which is why you see more attempts with a "Missing" value. Perhaps you have an issue with the way you're collection that information. Can you verify that you do/don't have records with a username but no workstation?

---

<div class="post-metadata">

**Author:** ![uklipse](https://avatars.discourse-cdn.com/v4/letter/u/cdc98d/32.png) [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Post date:** [November 8, 2018, 9:41pm UTC](https://discuss.elastic.co/t/kibana-visualaztion-data-table-missing-values/155957/5 "2018-11-08T21:41:39Z")

</div>

Yep, that was it. After looking at the data more closely, there are many fields that just have a dash instead of the workstation name so it's reading those as Missing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2018, 9:50pm UTC](https://discuss.elastic.co/t/kibana-visualaztion-data-table-missing-values/155957/6 "2018-12-06T21:50:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
