# Scripting field combining 2 fields

**URL:** <https://discuss.elastic.co/t/scripting-field-combining-2-fields/103630>\
**Category:** Kibana\
**Created:** [October 12, 2017, 1:18am UTC](https://discuss.elastic.co/t/scripting-field-combining-2-fields/103630 "2017-10-12T01:18:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rajinia](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@Rajinia](https://discuss.elastic.co/u/Rajinia)\
**Post date:** [October 12, 2017, 1:18am UTC](https://discuss.elastic.co/t/scripting-field-combining-2-fields/103630/1 "2017-10-12T01:18:04Z")

</div>

HI  
I want to create a scripting field with the combination of two fields and use in a Visualise graph.

so that I can use two fields in one bucket.

columns (A & B) are togeather unique  
trying to achive Logic like :- select count() form logs(kibana) where APIName(column A) =’xxx’ and APIVersionName =’x.0.0’ group by status code

Thanks for your help in advance

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [October 12, 2017, 7:45am UTC](https://discuss.elastic.co/t/scripting-field-combining-2-fields/103630/2 "2017-10-12T07:45:16Z")

</div>

Hey Rajinia,

you can create a scripted field, with the following painless script:

```auto
doc['APIName'].value + '_' + doc['APIVersionName'].value

```

That way you would get a field containing the name and the version in one field. If you use this you can now split up your buckets according to each name-version pair.

**Hint:** If this is a common use-case that you want to visualize over in your data, I would recommend you to add a field with that value at indexing time (e.g. modify your logstash config to add it, or whatever tool you are using). Adding it at indexing time will result in a way better performance, than scripted fields.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![Rajinia](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@Rajinia](https://discuss.elastic.co/u/Rajinia)\
**Post date:** [October 12, 2017, 10:21pm UTC](https://discuss.elastic.co/t/scripting-field-combining-2-fields/103630/3 "2017-10-12T22:21:47Z")

</div>

Thanks, Tim

Is there any way I can get a graph only for a specific API like " where API name =='aa' or API name =='bb'

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [October 13, 2017, 8:31am UTC](https://discuss.elastic.co/t/scripting-field-combining-2-fields/103630/4 "2017-10-13T08:31:06Z")

</div>

Yes, you can. Just add a filter on top of the visualization editor:

![screenshot-localhost-5601-2017-10-13-10-29-50-262](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a048c1daf0374ee4c70d1888a4cff1e40f4a4d7a.png)

If you save that visualization, that filter will keep attached to it, meaning if you place it on a dashboard it will still just show the results for that API you filtered it for.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2017, 8:31am UTC](https://discuss.elastic.co/t/scripting-field-combining-2-fields/103630/5 "2017-11-10T08:31:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
