# Remove null values from aggregated table visualization

**URL:** https://discuss.elastic.co/t/remove-null-values-from-aggregated-table-visualization/220190
**Category:** Kibana
**Created:** [February 20, 2020, 12:58pm UTC](https://discuss.elastic.co/t/remove-null-values-from-aggregated-table-visualization/220190 "2020-02-20T12:58:24Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![opellulo](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@opellulo](https://discuss.elastic.co/u/opellulo)
#### Post date: [February 20, 2020, 12:58pm UTC](https://discuss.elastic.co/t/remove-null-values-from-aggregated-table-visualization/220190/1 "2020-02-20T12:58:25Z")

</div>

Hi all,  
I have a simple visualization issue in Kibana that i suspect it's harder to fix than i thought, here is my situation:  
I have an index where the docs have different fields, however one of this field is common for all the docs. When in "Visualize" I create a simple table view aggregated for this common field I have my desired visualization; however when I request the top values for some other field I need, I obtain an hyphen ("-") value for the docs where this field is not present:  
 ![aggregate](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0ca0d9f8997442906397a03b528aa273e830dda6.png)

Now this would not be a problem if only for the fact that this null value is counted against the size limit of the aggregation, so to include all the values i want I have to raise a lot its limits and, even in this case, the visual output is a confused mess of commas and hyphens.

Is there a way to easily filter out the null values or have I to create a filter for each "top hit" aggregation? Bear in mind that i cannot filter the whole visualization because the fields I want can pop out in any doc (they are extracted using kv in logstash so i have no idea on how many they are or which docs contains them, the common filed is my only guide here).

In Splunk you can use the command "|where isnotnull(field) "and call it a day, but is there something similar in ELK?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 19, 2020, 12:58pm UTC](https://discuss.elastic.co/t/remove-null-values-from-aggregated-table-visualization/220190/2 "2020-03-19T12:58:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
