# Query to show all values in field where the sum of count for these values equal 0

**URL:** <https://discuss.elastic.co/t/query-to-show-all-values-in-field-where-the-sum-of-count-for-these-values-equal-0/63245>\
**Category:** Kibana\
**Created:** [October 18, 2016, 5:15am UTC](https://discuss.elastic.co/t/query-to-show-all-values-in-field-where-the-sum-of-count-for-these-values-equal-0/63245 "2016-10-18T05:15:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Houss](https://avatars.discourse-cdn.com/v4/letter/h/a88e4f/32.png) [@Houss](https://discuss.elastic.co/u/Houss)\
**Post date:** [October 18, 2016, 5:15am UTC](https://discuss.elastic.co/t/query-to-show-all-values-in-field-where-the-sum-of-count-for-these-values-equal-0/63245/1 "2016-10-18T05:15:51Z")

</div>

Hello,

I have a field _server\_name_ which return the name of the server that sends the log. What we want is create a graph that would show us all the servers that didn't send any logs for a specific timeframe. Would there be a way to do this ?

Thanks.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [October 18, 2016, 5:25pm UTC](https://discuss.elastic.co/t/query-to-show-all-values-in-field-where-the-sum-of-count-for-these-values-equal-0/63245/2 "2016-10-18T17:25:59Z")

</div>

Can you describe what you would like this visualization to look like? It might help define the setup needed for it. Thanks!

---

<div class="post-metadata">

**Author:** ![Houss](https://avatars.discourse-cdn.com/v4/letter/h/a88e4f/32.png) [@Houss](https://discuss.elastic.co/u/Houss)\
**Post date:** [October 18, 2016, 6:02pm UTC](https://discuss.elastic.co/t/query-to-show-all-values-in-field-where-the-sum-of-count-for-these-values-equal-0/63245/3 "2016-10-18T18:02:01Z")

</div>

Sorry that was indeed confusing on my part. Also, I think what I want is impossible to achieve but I will try to explain just in case it's not.  
I will use the field _file_ (generated by filebeat) instead of _server\_name_.  
I have a filebeat that will collect from several .log files (in the same diectory).  
What we want is a way to show us that one file hasn't sent any log in a 24h time frame for example.

Right now, if I make a table showing the counts for every values of _file_, it will show me all values that has at least one count. However, that means all the files that have 0 count won't show up at all.  
So basically we want a way to have these files appear in the table anyway.

Or maybe a way to query for those files, like "count\_sum:0" or something like that.

Thanks.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [October 18, 2016, 6:33pm UTC](https://discuss.elastic.co/t/query-to-show-all-values-in-field-where-the-sum-of-count-for-these-values-equal-0/63245/4 "2016-10-18T18:33:14Z")

</div>

Thanks for the explanation. I think I understand this better now.

Are the names of these files fixed, as in, do you know them when creating the visualization? If so, you might be able to accomplish what you want with a Filters Aggregation:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/ae5c724b78e49888aeb7e224045731b0e4db8355.png)

EDIT: See also [https://www.elastic.co/guide/en/elasticsearch/reference/2.4/search-aggregations-bucket-filters-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/search-aggregations-bucket-filters-aggregation.html) for how you can define each of the filters.

---

<div class="post-metadata">

**Author:** ![Houss](https://avatars.discourse-cdn.com/v4/letter/h/a88e4f/32.png) [@Houss](https://discuss.elastic.co/u/Houss)\
**Post date:** [October 19, 2016, 5:52am UTC](https://discuss.elastic.co/t/query-to-show-all-values-in-field-where-the-sum-of-count-for-these-values-equal-0/63245/5 "2016-10-19T05:52:17Z")

</div>

Wow, I didn't think of that at all, thanks a lot.  
The only problem is that it's not very agile (if more files are to be created later) but that's impressive already.

In case others get the same problem, here's the solution we adoped :  
We created a script that will create a file that will list all files in the directory with the count for everyone of them. Then we created extractors to return the value of the count. Then we created a graph with the query searching for all the files where the count equal 0 in a 24h timeframe (not sure is that's clear 😶 )

Regards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:36pm UTC](https://discuss.elastic.co/t/query-to-show-all-values-in-field-where-the-sum-of-count-for-these-values-equal-0/63245/6 "2017-07-06T13:36:17Z")

</div>


