# Need to filter out data which is greater than somehting

**URL:** <https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402>\
**Category:** Kibana\
**Created:** [December 19, 2017, 10:17am UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402 "2017-12-19T10:17:00Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 19, 2017, 10:17am UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/1 "2017-12-19T10:17:00Z")

</div>

Hi Guys,

I need to build visualization our of data where I need to filter out on one field which is greater than 1500. How do I do that can someone please advise?

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [December 19, 2017, 11:47am UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/2 "2017-12-19T11:47:06Z")

</div>

Which version of kibana are you using ? In latest versions in should be as simple as:

- click add new filter on the filter bar
- select the field you are interested in
- select `greater than` in the operation dropdown
- enter `1500` in the value field

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 19, 2017, 12:22pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/3 "2017-12-19T12:22:49Z")

</div>

are you talking about 6.x? I am still using 5.x. How is that possible in Kibana 5

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 19, 2017, 12:35pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/4 "2017-12-19T12:35:33Z")

</div>

to be specific its 5.6

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [December 19, 2017, 1:16pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/5 "2017-12-19T13:16:51Z")

</div>

you could type something like `fieldname: >1500` in the query bar

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 19, 2017, 2:10pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/6 "2017-12-19T14:10:16Z")

</div>

nah that is not happeining ☹

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [December 19, 2017, 2:16pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/7 "2017-12-19T14:16:30Z")

</div>

whats the result you are getting vs the result you are expecting ? could you copy paste request and response from spy panel (click the little up arrow at the bottom of your visualization)

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 19, 2017, 2:20pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/8 "2017-12-19T14:20:46Z")

</div>

here is the json which from Kibana

```
{

```

"\_index": "logstash-isnhp-2017.12.19",  
"\_type": "doc",  
"\_id": "AWBvFsZ3DOVoqfVcKq0O",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"lastseen": "last\_seen",  
"@timestamp": "2017-12-19T14:04:26.736Z",  
"geoip": {  
"timezone": "America/Los\_Angeles",  
"ip": "107.175.49.23",  
"latitude": 34.0494,  
"continent\_code": "NA",  
"city\_name": "Los Angeles",  
"country\_name": "United States",  
"country\_code2": "US",  
"dma\_code": 803,  
"country\_code3": "US",  
"region\_name": "California",  
"location": {  
"lon": -118.2641,  
"lat": 34.0494  
},  
"postal\_code": "90014",  
"region\_code": "CA",  
"longitude": -118.2641  
},  
"month": "12",  
"year": "2017",  
"@version": "1",  
"host": [  
"remote\_host"  
],  
"count": "count",  
"message": "{"remote\_host":"107.175.49.23","count":"2","last\_seen":"2017-12-19"}",  
"ipaddr": "107.175.49.23",  
"day": "19",  
"nooftimes": "2"  
},  
"fields": {  
"@timestamp": [  
1513692266736  
]  
},  
"highlight": {  
"nooftimes": [  
"@kibana-highlighted-field@2@/kibana-highlighted-field@"  
]  
},  
"sort": [  
1513692266736  
]  
}

DO you see "nooftimes": "2" I want to build a dashboard which has "nooftimes": "\> 1500"

here are the parsers

filter {  
grok {  
match =\> [ "message", '%{WORD:host}":"%{IPV4:ipaddr}","%{WORD:count}":"%{NUMBER:nooftimes}","%{WORD:lastseen}":"%{YEAR:year}-%{MONTHNUM:month}-%{MONTHDA  
Y:day}"' ]  
}  
geoip { source =\> "ipaddr" }

}

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [December 19, 2017, 2:41pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/9 "2017-12-19T14:41:49Z")

</div>

![screenshot-localhost-5601 2017-12-19 15-40-01-033](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e11afd4482b70b35187d82bc7833d26861836fb8.png)

open spy panel and copy paste Request and Response tabs. also please provide the exact thing you have in your query bar.

thanks

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [December 19, 2017, 2:46pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/10 "2017-12-19T14:46:42Z")

</div>

also, here is the documentation on lucene query syntax (which query bar uses)

[https://www.elastic.co/guide/en/elasticsearch/reference/5.6/query-dsl-query-string-query.html#query-string-syntax](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/query-dsl-query-string-query.html#query-string-syntax)

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 19, 2017, 2:47pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/11 "2017-12-19T14:47:56Z")

</div>

Yep I am trying that but somehow dang the query is not working out...or lets say I want to filter out events in discover tab instead of building visualization or dashboard

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [December 19, 2017, 2:51pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/12 "2017-12-19T14:51:53Z")

</div>

from the document you passed it looks like nooftimes is indexed as string, should be indexed as number for this to work

can you check management-\>index patterns-\>select your index pattern and locate your field ... what type is it ?

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 19, 2017, 2:52pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/13 "2017-12-19T14:52:44Z")

</div>

Yeah that is correct its parsed as a string..though if you check in my logstash config this has been parsed as a NUMBER. What it should be then? Or can I edit that in kibana?

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [December 19, 2017, 2:56pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/14 "2017-12-19T14:56:14Z")

</div>

that won't define how the field is indexed in elasticsearch.

elasticsearch does auto recognize the field type based on **the first indexed document**

so if your first document had a string in that place, that will be string for all the following documents.

there is a way to force the field type using the [elastic search mappings](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/mapping.html)

at this point you will probably need to reindex all your documents to get this to work.

you could also use [scripted fields](https://www.elastic.co/guide/en/kibana/5.6/scripted-fields.html) to do the conversion on-the-fly, however that will use a lot of resources and might not be performant enough (specially if your dataset is big)

---

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [December 19, 2017, 2:59pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/15 "2017-12-19T14:59:08Z")

</div>

hmm thats right..this may be the issue with the template I used? I Guess mapping was done using that template.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2018, 2:59pm UTC](https://discuss.elastic.co/t/need-to-filter-out-data-which-is-greater-than-somehting/112402/16 "2018-01-16T14:59:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
