# Query Conditionally Between Fields

**URL:** <https://discuss.elastic.co/t/query-conditionally-between-fields/298294>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [February 25, 2022, 3:13pm UTC](https://discuss.elastic.co/t/query-conditionally-between-fields/298294 "2022-02-25T15:13:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_PA](https://avatars.discourse-cdn.com/v4/letter/_/90ced4/32.png) [@\_PA](https://discuss.elastic.co/u/_PA)\
**Post date:** [February 25, 2022, 3:13pm UTC](https://discuss.elastic.co/t/query-conditionally-between-fields/298294/1 "2022-02-25T15:13:58Z")

</div>

Hi,

I want to know if it is possible to perform a query in kibana to get the following results.  
I have a records that have common values between them and I want to query and get the results for the records that have more than one association.  
Because this is difficult to explain, I share and example below with tables from Excel.  
Initially it look like this:

 ![doubt_kibana2](https://us1.discourse-cdn.com/elastic/original/3X/b/a/ba6aea67b4b36ff17846c750dd96f0308626f79e.png)

I want to query in a way that I get the `AAA` that have more then one `BBB`.  
So it will look like this:

 ![doubt_kibana3](https://us1.discourse-cdn.com/elastic/original/3X/3/6/36d58581b8f79f3d46c2dca4bb903f57548c240d.png)

Is this possible in Kibana?

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [February 25, 2022, 3:33pm UTC](https://discuss.elastic.co/t/query-conditionally-between-fields/298294/2 "2022-02-25T15:33:01Z")

</div>

You might run into problems with that screenshot because you have non-numbers in `BBB` - but if I ignore those...you could potentially use a runtime field to compare two documents and emit a true / false....and then use that true / false field to filter to only the documents where the condition is true.

```auto
//Return a true when one field is greater than another in the same document
if (doc['AAA'].size()==0) {
    emit(false);
}
else if (doc['BBB'].size()==0) {
    emit(false);
}
else {
    if (doc['AAA'].value > doc['BBB'].value) {
        emit(true);
    }
    else {
        emit(false);
    }
}

```

You can enter this in a runtime field editor in Stack Management, Discover, or Lens

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/f/7f6e682e8d53a19f70950d26b5dd56c4d5f7735a.png)

---

<div class="post-metadata">

**Author:** ![\_PA](https://avatars.discourse-cdn.com/v4/letter/_/90ced4/32.png) [@\_PA](https://discuss.elastic.co/u/_PA)\
**Post date:** [February 25, 2022, 3:46pm UTC](https://discuss.elastic.co/t/query-conditionally-between-fields/298294/3 "2022-02-25T15:46:28Z")

</div>

Thanks for the quick reply! Can I do this on a Visualization in? Like create the field temporarily?

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [February 25, 2022, 3:51pm UTC](https://discuss.elastic.co/t/query-conditionally-between-fields/298294/4 "2022-02-25T15:51:31Z")

</div>

Not yet but it's something we have been talking about doing. "Local runtime fields" [[Runtime Fields] [META] Runtime Fields UX · Issue #124412 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/124412) - CC @Jason_Burns for 👀

---

<div class="post-metadata">

**Author:** ![\_PA](https://avatars.discourse-cdn.com/v4/letter/_/90ced4/32.png) [@\_PA](https://discuss.elastic.co/u/_PA)\
**Post date:** [February 25, 2022, 3:59pm UTC](https://discuss.elastic.co/t/query-conditionally-between-fields/298294/5 "2022-02-25T15:59:08Z")

</div>

I am running an enterprise edition and I do not think I have the possibility to create a field. Is there another way of achieving this?  
This is what my stack management looks like:  
 ![Captura de ecrã 2022-02-25 160349](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e9a5cc04d4b1ab3f78ad783d5bca145698beab3.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2022, 3:59pm UTC](https://discuss.elastic.co/t/query-conditionally-between-fields/298294/6 "2022-03-25T15:59:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
