# Performing aggregation on field values via Kibana not working

**URL:** <https://discuss.elastic.co/t/performing-aggregation-on-field-values-via-kibana-not-working/92746>\
**Category:** Kibana\
**Created:** [July 12, 2017, 2:25am UTC](https://discuss.elastic.co/t/performing-aggregation-on-field-values-via-kibana-not-working/92746 "2017-07-12T02:25:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AtShar](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@AtShar](https://discuss.elastic.co/u/AtShar)\
**Post date:** [July 12, 2017, 2:25am UTC](https://discuss.elastic.co/t/performing-aggregation-on-field-values-via-kibana-not-working/92746/1 "2017-07-12T02:25:14Z")

</div>

I am using Elasticsearch 5.4.1 and Kibana 5.4.1 . When I try to perform filter aggregations on field values using `fieldName:fieldValue` , I get no results.However when I only enter the `fieldValue` as a filter I obtain a list with matching field values from all the fields.

I captured the request using chrome developer tools.Following request is fired when I use `fieldName:fieldValue` (Response Status:200 , where Response Status is field with values 200,400,500)

{"index":"logstash-_","ignore\_unavailable":true,"preference":1499662909171}  
{"query":{"bool":{"must":[{"query\_string":{"analyze\_wildcard":true,"query":"_"}},{"range":{"@timestamp":{"gte":1499612400000,"lte":1499698799999,"format":"epoch\_millis"}}}],"must\_not":[]}},"size":0,"\_source":{"excludes":[]},"aggs":{"2":{"date\_histogram":{"field":"@timestamp","interval":"1h","time\_zone":"Asia/Tokyo","min\_doc\_count":1},"aggs":{"3":{"filters":{"filters":{"Success":{"query\_string":{ **"query":"Response Status:200"** ,"analyze\_wildcard":true}},"Failed":{"query\_string":{"query":"-Response Status:200","analyze\_wildcard":true}}}}}}}}}

But when I use only `fieldValue` (200) below request is fired:

{"index":"logstash-_","ignore\_unavailable":true,"preference":1499662909171}  
{"query":{"bool":{"must":[{"query\_string":{"analyze\_wildcard":true,"query":"_"}},{"range":{"@timestamp":{"gte":1499612400000,"lte":1499698799999,"format":"epoch\_millis"}}}],"must\_not":[]}},"size":0,"\_source":{"excludes":[]},"aggs":{"2":{"date\_histogram":{"field":"@timestamp","interval":"1h","time\_zone":"Asia/Tokyo","min\_doc\_count":1},"aggs":{"3":{"filters":{"filters":{"Success":{"query\_string":{ **"query":"200"** ,"analyze\_wildcard":true}},"Failed":{"query\_string":{"query":"-200","analyze\_wildcard":true}}}}}}}}}

I am not able to figure out the issue.  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [July 12, 2017, 11:13pm UTC](https://discuss.elastic.co/t/performing-aggregation-on-field-values-via-kibana-not-working/92746/2 "2017-07-12T23:13:50Z")

</div>

The problem is that the field name has a space in it, so the query is basically the same as "anything with the word 'Response', and a 200 in the 'Status' field"

Try using the query string `Response\ Status:200`, the `\` escapes the space so that the field name is identified correctly.

---

<div class="post-metadata">

**Author:** ![AtShar](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@AtShar](https://discuss.elastic.co/u/AtShar)\
**Post date:** [July 13, 2017, 2:05am UTC](https://discuss.elastic.co/t/performing-aggregation-on-field-values-via-kibana-not-working/92746/3 "2017-07-13T02:05:14Z")

</div>

Thank you for the response. It solved my problem.😌

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2017, 2:05am UTC](https://discuss.elastic.co/t/performing-aggregation-on-field-values-via-kibana-not-working/92746/4 "2017-08-10T02:05:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
