# Regarding count lookup of newly defined fields with log stash

**URL:** <https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814>\
**Category:** Logstash\
**Created:** [June 22, 2022, 12:33am UTC](https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814 "2022-06-22T00:33:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![inwoo1](https://avatars.discourse-cdn.com/v4/letter/i/ed655f/32.png) [@inwoo1](https://discuss.elastic.co/u/inwoo1)\
**Post date:** [June 22, 2022, 12:33am UTC](https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814/1 "2022-06-22T00:33:57Z")

</div>

I am collecting SNMP through logstash and creating a new field forti\_fw\_sessioncount through mutate-rename function.

Looking at the log, 791 cases of forti\_fw\_sessioncount came in, but only 29 cases were shown when I checked with 'visualize' in the same time period. How do I make 791 cases appear normally?

 ![1](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1adadd9941b3e22eb3bf8324ecca3a4043d485ef.png)

 ![2](https://us1.discourse-cdn.com/elastic/original/3X/2/f/2f80fb23e37f7873e44184589fb6c368910a0cd3.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 22, 2022, 12:35am UTC](https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814/2 "2022-06-22T00:35:14Z")

</div>

Are you sure the timeframe for the visualisation is correct?

---

<div class="post-metadata">

**Author:** ![inwoo1](https://avatars.discourse-cdn.com/v4/letter/i/ed655f/32.png) [@inwoo1](https://discuss.elastic.co/u/inwoo1)\
**Post date:** [June 22, 2022, 12:48am UTC](https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814/3 "2022-06-22T00:48:28Z")

</div>

yes that is correct Strangely, when I look at 'visualize', only values ​​between 28 and 30 keep appearing. Why is this like this?

As the search time increases, the number of cases seems to increase accordingly. It seems that the number of 'forti\_fw\_sessioncount' is not displayed, but the number of snmps.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 22, 2022, 2:32am UTC](https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814/4 "2022-06-22T02:32:04Z")

</div>

I think you are looking at two different things.

The left side of your screenshot shows a document where the field `fort_fw_sessioncount` has the value of `791`.

In the right side you have a visualization that is a Unique count of the values that the field `fort_fw_sessioncount` have, this means that in your index, the field `fort_fw_sessioncount` has 29 different values in the documents where the host is `10.0.0.1`, one of them is the example you shared where it has the value of `791`.

For example, if you have only five documents for the host `10.0.0.1` with the following values for `fort_fw_sessioncount`:

```auto
{ "_id": "1", "fort_fw_sessioncount": "791", "host": "10.0.0.1" }
{ "_id": "2", "fort_fw_sessioncount": "791", "host": "10.0.0.1" }
{ "_id": "3", "fort_fw_sessioncount": "792", "host": "10.0.0.1" }
{ "_id": "4", "fort_fw_sessioncount": "792", "host": "10.0.0.1" }
{ "_id": "5", "fort_fw_sessioncount": "792", "host": "10.0.0.1" }

```

Your visualization with Unique count for the field `fort_fw_sessioncount` will show only `2`, because you would have only 2 different, `791` and `792`.

What you expect to see in the visualization?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2022, 2:32am UTC](https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814/5 "2022-07-20T02:32:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
