# Kibana visualization - Count occurence of term in multiple fields

**URL:** <https://discuss.elastic.co/t/kibana-visualization-count-occurence-of-term-in-multiple-fields/244405>\
**Category:** Kibana\
**Created:** [August 10, 2020, 1:02pm UTC](https://discuss.elastic.co/t/kibana-visualization-count-occurence-of-term-in-multiple-fields/244405 "2020-08-10T13:02:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ilya\_Geller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilya_geller/32/52615_2.png) [@Ilya\_Geller](https://discuss.elastic.co/u/Ilya_Geller)\
**Post date:** [August 10, 2020, 1:02pm UTC](https://discuss.elastic.co/t/kibana-visualization-count-occurence-of-term-in-multiple-fields/244405/1 "2020-08-10T13:02:51Z")

</div>

Hello,  
I have index that containts documents with fields: `source_address` and `destination_address` for each event.

I would like to create a visualization in Kibana to show the top 10 most popular addresses in the database, both source and destination together.  
To clarify, I do not mean create a chart for top 10 source addresses and a separate one for destination, but instead count how many times an address has **occured at all (either in source or destination)** and display the top values of that.

How can this be achieved?

Thanks.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 10, 2020, 1:24pm UTC](https://discuss.elastic.co/t/kibana-visualization-count-occurence-of-term-in-multiple-fields/244405/2 "2020-08-10T13:24:16Z")

</div>

You can't do this purely with aggregations, but there are two options:

- Create a scripted field which returns an array of source and destination address: [https://www.elastic.co/guide/en/kibana/current/scripted-fields.html](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html) Then use "unique count" on this scripted field
- If the first option is too slow, do the same thing at ingest time by using `copy_to` in your mapping: [https://www.elastic.co/guide/en/elasticsearch/reference/current/copy-to.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/copy-to.html)

For the second option you have to reindex your existing data, but it will scale better if you have large amounts of data

---

<div class="post-metadata">

**Author:** ![Ilya\_Geller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilya_geller/32/52615_2.png) [@Ilya\_Geller](https://discuss.elastic.co/u/Ilya_Geller)\
**Post date:** [August 10, 2020, 1:51pm UTC](https://discuss.elastic.co/t/kibana-visualization-count-occurence-of-term-in-multiple-fields/244405/3 "2020-08-10T13:51:11Z")

</div>

Thank you for the reply.

Won't "unique count" over this array field count the unique occurence of the pair [src,dst] together? I would like to achieve the count of docs where `src=X or dest=X` , not `src=X and dest=Y` , if this makes sense.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 11, 2020, 7:17am UTC](https://discuss.elastic.co/t/kibana-visualization-count-occurence-of-term-in-multiple-fields/244405/4 "2020-08-11T07:17:06Z")

</div>

No, Elasticsearch will treat each value of the array separately. You can simply use the "terms" aggregation to get the list of the top addresses:

```auto
POST myindex/_doc
{
  "myField": ["a", "b"]
}

POST myindex/_doc
{
  "myField": ["b", "c"]
}

POST myindex/_doc
{
  "myField": ["c", "d"]
}

GET myindex/_search?size=0
{
  "aggs": {
    "terms": {
      "terms": {
        "field": "myField.keyword",
        "size": 2
      }
    }
  }
}

// Result
      "buckets" : [
        {
          "key" : "b",
          "doc_count" : 2
        },
        {
          "key" : "c",
          "doc_count" : 2
        }
      ]

```

---

<div class="post-metadata">

**Author:** ![Ilya\_Geller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilya_geller/32/52615_2.png) [@Ilya\_Geller](https://discuss.elastic.co/u/Ilya_Geller)\
**Post date:** [August 11, 2020, 7:37am UTC](https://discuss.elastic.co/t/kibana-visualization-count-occurence-of-term-in-multiple-fields/244405/5 "2020-08-11T07:37:39Z")

</div>

That did the trick. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2020, 7:37am UTC](https://discuss.elastic.co/t/kibana-visualization-count-occurence-of-term-in-multiple-fields/244405/6 "2020-09-08T07:37:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
