# Replicating Splunk query

**URL:** <https://discuss.elastic.co/t/replicating-splunk-query/96158>\
**Category:** Kibana\
**Created:** [August 7, 2017, 9:43pm UTC](https://discuss.elastic.co/t/replicating-splunk-query/96158 "2017-08-07T21:43:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shroh](https://avatars.discourse-cdn.com/v4/letter/s/74df32/32.png) [@shroh](https://discuss.elastic.co/u/shroh)\
**Post date:** [August 7, 2017, 9:43pm UTC](https://discuss.elastic.co/t/replicating-splunk-query/96158/1 "2017-08-07T21:43:00Z")

</div>

Hi I have injested my data into ELK and i can see the data in Kibana as well.

in splunk i have this query

index=app "verifyStatusCode" | stats ExecutionTime

I can see the ExecutionTime field in kibana as per my GROK filter, now i want to just visualise the same thing in ELK Single Value visualisation, by searching for events which have "verifyStatusCode" and their Execution time.

Need help in writing the Elastic search query for this one.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [August 8, 2017, 1:23pm UTC](https://discuss.elastic.co/t/replicating-splunk-query/96158/2 "2017-08-08T13:23:04Z")

</div>

Hello,  
Where do you want to write the query for this in Kibana? In the filter json input or in the search bar?  
Also, what version of Kibana are you using? (as there may be deprecations in query syntax between versions). Also, you can check out the latest 6.0.0 beta (should come out soon) that has a visual filter builder.

---

<div class="post-metadata">

**Author:** ![shroh](https://avatars.discourse-cdn.com/v4/letter/s/74df32/32.png) [@shroh](https://discuss.elastic.co/u/shroh)\
**Post date:** [August 8, 2017, 1:42pm UTC](https://discuss.elastic.co/t/replicating-splunk-query/96158/3 "2017-08-08T13:42:22Z")

</div>

Yes i want to create using the search bar. How do we create using the JSON input?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [August 8, 2017, 5:48pm UTC](https://discuss.elastic.co/t/replicating-splunk-query/96158/4 "2017-08-08T17:48:10Z")

</div>

You can create a filter in Kibana like this:  
[https://www.elastic.co/guide/en/beats/packetbeat/current/kibana-queries-filters.html](https://www.elastic.co/guide/en/beats/packetbeat/current/kibana-queries-filters.html)  
once you create it, that filter can be edited and you can modify it's JSON object.  
This is a guide to QueryDSL which is used in the filter syntax:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#query-string-syntax](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#query-string-syntax)

You need `_exists_" from there for the`verifyStatusCode` field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 5, 2017, 5:48pm UTC](https://discuss.elastic.co/t/replicating-splunk-query/96158/5 "2017-09-05T17:48:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
