# Representing the Document values in Kibana table

**URL:** <https://discuss.elastic.co/t/representing-the-document-values-in-kibana-table/88060>\
**Category:** Kibana\
**Created:** [June 2, 2017, 10:12am UTC](https://discuss.elastic.co/t/representing-the-document-values-in-kibana-table/88060 "2017-06-02T10:12:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mussa572](https://avatars.discourse-cdn.com/v4/letter/m/a698b9/32.png) [@mussa572](https://discuss.elastic.co/u/mussa572)\
**Post date:** [June 2, 2017, 10:12am UTC](https://discuss.elastic.co/t/representing-the-document-values-in-kibana-table/88060/1 "2017-06-02T10:12:50Z")

</div>

We are parsing ASA logs in Elastic search in following format . Around 1000 logs per minutes are ingested into elasticsearch . My requirement is to able to take each message and show them real time in Kibana table to users so they can search the values from table . We want table to represent each message in the following format

timestamp , src\_ip , dst\_ip ,src\_port, dst\_port,action , ciscotag, reason , cisco message ,hashcode1 ,hashcode2

I have tried to create the table using Term aggregation , however I have seen an issue when ,hashcode1 ,hashcode2 missing from the message ( which is normal ) I dont see any values in the table .

I was wondering if there is any way where I match the \_id of each document and populate all the required values int the table and if any value missing from the document , it should just ignore .

@timestamp June 1st 2017, 18:48:58.258t  
@version 1  
\_id AVxkxlQcZZ8zmTPO84Aq  
\_index logstash\_asalogs-2017.06.01  
\_score -  
\_type cisco-fw  
action permitted  
cisco\_message access-list external\_access\_in permitted udp external/10.135.1.12(62525) -\> inside/10.138.7.14(53) hit-cnt 1 first hit [0xde8dd1d7, 0xbb4301cd]

ciscotag ASA-6-106100  
dst\_interface inside  
dst\_ip 10.138.7.14  
dst\_port 53  
**hashcode1 0xde8dd1d7**  
\*\* hashcode2 0xbb4301cd\*\*  
hit\_count 1  
host 10.138.252.14  
interval first hit  
message \<182\>Jun 01 2017 18:48:58: %ASA-6-106100: access-list external\_access\_in permitted udp external/10.135.1.12(62525) -\> inside/10.138.7.14(53) hit-cnt 1 first hit [0xde8dd1d7, 0xbb4301cd]  
policy\_id external\_access\_in  
protocol udp  
src\_interface external  
src\_ip 10.135.1.12  
src\_port 62525  
syslog\_facility local6  
syslog\_facility\_code 22  
syslog\_pri 182  
syslog\_severity informational  
syslog\_severity\_code 6  
tags pre-processed, Firewall, ASA, \_geoip\_lookup\_failure  
timestamp Jun 01 2017 18:48:58  
type cisco-fw

* * *

Below the table setting in Kibana

 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/2/229b74a8fdadc60212754484f24c2538f90c3496.png)

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [June 2, 2017, 12:35pm UTC](https://discuss.elastic.co/t/representing-the-document-values-in-kibana-table/88060/2 "2017-06-02T12:35:43Z")

</div>

Hello,  
The solution that I see to your problem is to create 2 filters on the dashboard(easiest way to do there) that have "exist" for both of your fields: hashcode1 and hashcode2.  
The way you do this is to expand a document on the discover page that contains these fields and the click on the asterisk next to the field name (4th icon that row) which does "Filter for field present". After that you need to pin the filters so that they are available on the datatable as well.  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/3/0/3008012c2b3cce91dc6f2f4445ed674fdcd7d49d.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2017, 12:36pm UTC](https://discuss.elastic.co/t/representing-the-document-values-in-kibana-table/88060/3 "2017-06-30T12:36:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
