# Plot with filter

**URL:** <https://discuss.elastic.co/t/plot-with-filter/130998>\
**Category:** Kibana\
**Created:** [May 8, 2018, 12:11pm UTC](https://discuss.elastic.co/t/plot-with-filter/130998 "2018-05-08T12:11:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ventrca](https://avatars.discourse-cdn.com/v4/letter/v/a87d85/32.png) [@ventrca](https://discuss.elastic.co/u/ventrca)\
**Post date:** [May 8, 2018, 12:11pm UTC](https://discuss.elastic.co/t/plot-with-filter/130998/1 "2018-05-08T12:11:03Z")

</div>

Hi,

I'm trying to create a simple visualization:  
it's a chart line but where I want to consider in the aggregation only the logs that have to equal fields (that in this case are keyword).

I'm able to create the ES query but I need to plot it.

```
{
  "query": { 
    "bool": { 
      "must": [
        { "exists": { "field":"A"}},
        { "script" : {
          "script" : "doc['A.keyword'].value != doc['B.keyword'].value"
          }
        }
      ]
    }
  }
}

```

Thank you

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [May 8, 2018, 1:23pm UTC](https://discuss.elastic.co/t/plot-with-filter/130998/2 "2018-05-08T13:23:38Z")

</div>

Try putting that query in the `Edit Query DSL` portion of the `Add filter` dialog:

 ![14%20AM](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f02cf11fde9b993b872b723a0417c8710601acb.png)

---

<div class="post-metadata">

**Author:** ![ventrca](https://avatars.discourse-cdn.com/v4/letter/v/a87d85/32.png) [@ventrca](https://discuss.elastic.co/u/ventrca)\
**Post date:** [May 8, 2018, 2:13pm UTC](https://discuss.elastic.co/t/plot-with-filter/130998/3 "2018-05-08T14:13:49Z")

</div>

Thank you for the quick answer,  
this works very well, but what if I want a visualization where in the same graph I there are two lines, one with the filtered values, and one with all the values?

---

<div class="post-metadata">

**Author:** ![ventrca](https://avatars.discourse-cdn.com/v4/letter/v/a87d85/32.png) [@ventrca](https://discuss.elastic.co/u/ventrca)\
**Post date:** [May 11, 2018, 9:31am UTC](https://discuss.elastic.co/t/plot-with-filter/130998/4 "2018-05-11T09:31:37Z")

</div>

@Stacey_Gammon there's no way to do this?

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [May 23, 2018, 12:47pm UTC](https://discuss.elastic.co/t/plot-with-filter/130998/5 "2018-05-23T12:47:23Z")

</div>

Might be able to do something in timelion, the expression language allows for a lot of flexibility and it's for time series data. Perhaps worth exploring!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2018, 12:47pm UTC](https://discuss.elastic.co/t/plot-with-filter/130998/6 "2018-06-20T12:47:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
