# Kibana visualization and foreach?

**URL:** <https://discuss.elastic.co/t/kibana-visualization-and-foreach/110708>\
**Category:** Kibana\
**Created:** [December 7, 2017, 3:39pm UTC](https://discuss.elastic.co/t/kibana-visualization-and-foreach/110708 "2017-12-07T15:39:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![brandondash](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@brandondash](https://discuss.elastic.co/u/brandondash)\
**Post date:** [December 7, 2017, 3:39pm UTC](https://discuss.elastic.co/t/kibana-visualization-and-foreach/110708/1 "2017-12-07T15:39:51Z")

</div>

I found the foreach processor for Elasticsearch, but I am wondering if that same ability exists in the Kibana UI?

My use case is that I save a search for the creation of a meeting with a unique meetingId. Now, for each meetingId I'd like to create a visualization that presents data of the users. In the logs this is captured by a UserJoinedEvent with the meetingId and the userId.

Is this possible?

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [December 9, 2017, 12:17am UTC](https://discuss.elastic.co/t/kibana-visualization-and-foreach/110708/2 "2017-12-09T00:17:31Z")

</div>

Hi Brandon,

The foreach processor is for preprocessing documents before they're indexed in Elasticsearch, and no such functionality exists in Kibana. I'm a bit confused about what you're asking for here.

> Now, for each meetingId I'd like to create a visualization that presents data of the users

It sounds like you want to dynamically generate visualizations based on the data set returned by a query. Kibana doesn't support this in the UI, but you could write some scripts or use automation tools to do this. Here's some information about the API you'll need to hit: [https://github.com/elastic/kibana/pull/11632](https://github.com/elastic/kibana/pull/11632).

You can GET a visualization using this API to see what kind of payload you'd need to send to create it. For example:

```auto
curl -H "Content-Type: application/json" -H "kbn-xsrf: true" http://localhost:5601/api/saved_objects/visualization/{visualization ID}

```

You can find the visualization ID by opening up the visualization in Kibana and looking for the ID in the URL:

```auto
http://localhost:5601/app/kibana#/visualize/edit/{visualization ID}

```

Hope this helps,  
CJ

---

<div class="post-metadata">

**Author:** ![brandondash](https://avatars.discourse-cdn.com/v4/letter/b/76d3ee/32.png) [@brandondash](https://discuss.elastic.co/u/brandondash)\
**Post date:** [December 12, 2017, 8:26pm UTC](https://discuss.elastic.co/t/kibana-visualization-and-foreach/110708/3 "2017-12-12T20:26:41Z")

</div>

> It sounds like you want to dynamically generate visualizations based on the data set returned by a query.

I am OK with the data being static by the time I want to visualize, but that would require subqueries.

Does Kibana support sql-style subqueries? My forum searches have all returned the answer "no" but that has been for Kibana 4.x and earlier.

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [December 12, 2017, 9:03pm UTC](https://discuss.elastic.co/t/kibana-visualization-and-foreach/110708/4 "2017-12-12T21:03:53Z")

</div>

Sorry Brandon, Kibana doesn't support sql-style subqueries.

CJ

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2018, 9:04pm UTC](https://discuss.elastic.co/t/kibana-visualization-and-foreach/110708/5 "2018-01-09T21:04:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
