# Multiple terms in a single histogram

**URL:** <https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862>\
**Category:** Kibana\
**Created:** [September 29, 2016, 8:30pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862 "2016-09-29T20:30:48Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [September 29, 2016, 8:30pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/1 "2016-09-29T20:30:48Z")

</div>

Topic says it. I have two string fields, service and protosigs that I'd like to use as a. I can get one (service):

 ![](https://us1.discourse-cdn.com/elastic/original/2X/7/7989a9c230a202f3262ed9118a7b34fc72578ff1.jpg)

or the other (protosigs):

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/468f594d9ea4c5be45cf3ea74710cd8a4bf44969.jpg)

But not both. Is there a way I can do this with the below? Thank you.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0117f1d5ae81889e4a53a792919b244af3b2fc1a.jpg)

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [October 5, 2016, 10:01pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/2 "2016-10-05T22:01:58Z")

</div>

Unfortunately no, this is a limitation of the terms aggregation: [https://www.elastic.co/guide/en/elasticsearch/reference/5.0/search-aggregations-bucket-terms-aggregation.html#\_multi\_field\_terms\_aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/5.0/search-aggregations-bucket-terms-aggregation.html#_multi_field_terms_aggregation)

The best way to solve this would be to combine the fields at ingestion time using Logstash, [Ingest Node](https://www.elastic.co/guide/en/elasticsearch/reference/5.0/ingest.html) (5.0), or `copy_to` (as mentioned in the linked doc).

The scripted field workaround could work after ingestion time, but it would require some changes in Kibana. For one you'll need support for the Painless scripting language, which was added in 5.0. The other piece is [support for non-value scripts](https://github.com/elastic/kibana/issues/7879), which we have not yet implemented.

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 7, 2016, 9:54pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/3 "2016-10-07T21:54:09Z")

</div>

Thanks Matt...I think I'll give Ingest Node a whirl as I'm using 5 beta. I'm assuming I can assign that to a template yes?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [October 7, 2016, 10:52pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/4 "2016-10-07T22:52:26Z")

</div>

Sorry, I'm not sure exactly what you mean by assign it to a template. Can you elaborate?

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [October 7, 2016, 11:12pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/5 "2016-10-07T23:12:56Z")

</div>

Timelion (a plugin for 4.x, built-in for 5.0) can chart multiple queries on the same chart. You might want to try that.

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 8, 2016, 11:03am UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/6 "2016-10-08T11:03:44Z")

</div>

Ah...well...my plan was to include that in template similar to a mapping template. Is there a different way to get this to apply to all indexes doing forward? In reading it looks like Join preprocesser will be just the ticket.

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 8, 2016, 11:04am UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/7 "2016-10-08T11:04:01Z")

</div>

Thanks Lee...I'll take a look at that as well.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [October 10, 2016, 2:48pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/8 "2016-10-10T14:48:06Z")

</div>

For now you have to add a param to the indexing request, as shown [here](https://www.elastic.co/guide/en/elasticsearch/reference/5.0/ingest.html). There was talk of allowing pipelines to be configured in index templates but I don't believe it was ever implemented. If you're interested in that feature I'd create a ticket on the [ES github repo](https://github.com/elastic/elasticsearch).

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 10, 2016, 3:11pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/9 "2016-10-10T15:11:40Z")

</div>

Ah....so are you saying I have to do this request from within Kibana? How does one do that? And thanks Matt for taking the time to walk me through this stuff.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [October 10, 2016, 3:57pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/10 "2016-10-10T15:57:38Z")

</div>

np! You won't do it from inside Kibana, but from whatever tool you're using to send data to ES. Are you using logstash or beats perhaps?

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 10, 2016, 4:10pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/11 "2016-10-10T16:10:43Z")

</div>

Ah cool...this is new territory for me. This will be using logstash. Thanks Mett!

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [October 10, 2016, 4:32pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/12 "2016-10-10T16:32:08Z")

</div>

Cool, in that case you'll just need to set the [pipeline config](https://www.elastic.co/guide/en/logstash/5.0/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-pipeline) in your logstash output config.

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 10, 2016, 4:45pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/13 "2016-10-10T16:45:09Z")

</div>

Beautiful...thanks again Matt!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:37pm UTC](https://discuss.elastic.co/t/multiple-terms-in-a-single-histogram/61862/14 "2017-07-06T13:37:08Z")

</div>


