# Search based on variables' count

**URL:** <https://discuss.elastic.co/t/search-based-on-variables-count/47004>\
**Category:** Kibana\
**Created:** [April 11, 2016, 3:20pm UTC](https://discuss.elastic.co/t/search-based-on-variables-count/47004 "2016-04-11T15:20:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mirnuj\_atom](https://avatars.discourse-cdn.com/v4/letter/m/7c8e57/32.png) [@mirnuj\_atom](https://discuss.elastic.co/u/mirnuj_atom)\
**Post date:** [April 11, 2016, 3:20pm UTC](https://discuss.elastic.co/t/search-based-on-variables-count/47004/1 "2016-04-11T15:20:07Z")

</div>

Hey Guys

I have the following json structure saved under variable in elastic:

`accounts_info { "server": "localhost", "type": "encrypt" }, { "server": "localhost", "type": "decrypt" }`

Number of such short jsons saved under "accounts\_info" varies.  
I need to filter out all the results where accounts\_info.type appears more than once to build a graph. Is it possible to search for something like "value\_count:"accounts\_info.type"\>1" in Kibana?

Thank you.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [April 11, 2016, 7:06pm UTC](https://discuss.elastic.co/t/search-based-on-variables-count/47004/2 "2016-04-11T19:06:34Z")

</div>

Hi Andrii,

On a Visualization you can aggregate by that count and see the top N results. With the right "N" you would only the results where count \> 1. But you would have to adjust that "N" every time the data changes. In the screenshot below, there are more than 4 machine.os.raw types, but I set the "Size" to 4. So it's only showing me the top 4 counts for that field.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/5/55e7018890e86f796c581cd568f49886aed88e9e.png)

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![mirnuj\_atom](https://avatars.discourse-cdn.com/v4/letter/m/7c8e57/32.png) [@mirnuj\_atom](https://discuss.elastic.co/u/mirnuj_atom)\
**Post date:** [April 12, 2016, 9:09am UTC](https://discuss.elastic.co/t/search-based-on-variables-count/47004/3 "2016-04-12T09:09:24Z")

</div>

Hey Lee

Thank you for the reply.

That is not quite what I am after though.  
What I need is to count how many fields "accounts\_info.type" in a single event (it is decrypted from payload and can have several nested json structures).  
I.E, one event can look like this:  
`accounts_info { "server": "localhost", "type": "encrypt" }`  
And other like this:  
`accounts_info { "server": "myserver.com", "type": "encrypt", "decrypted": 1 }, { "type": "decrypt" }, { "type": "decrypt" }`

So the first event has one accounts\_info.type field and the second three, what I need is to divide those events which have only one "type" field (which means a single account added to our application by user) from those which have more than one.

Sorry for my poor English 😉

Andrii.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [April 12, 2016, 3:45pm UTC](https://discuss.elastic.co/t/search-based-on-variables-count/47004/4 "2016-04-12T15:45:09Z")

</div>

Hi Andrii,

Here's an example where someone else counted the number of a type of element in their data;  
[http://elasticsearch-users.115913.n3.nabble.com/Count-number-of-array-element-for-each-document-td4056082.html](http://elasticsearch-users.115913.n3.nabble.com/Count-number-of-array-element-for-each-document-td4056082.html)

But that example is only talking about Elasticsearch. To use a script to get the count of your "type" I think you would have to use the JSON script field in the Kibana visualizations. Click on the Advanced link at the bottom of the aggregations to see it.

Here's an example of using a JSON script in Kibana;

> [@Display concurrency in data on Kibana](https://discuss.elastic.co/t/display-concurrency-in-data-on-kibana/26006/12):
>
> I also tried this but it doesn't remove the field parameter as promised. With the following json input: { "interval":"minute", "script": "start = doc['recordStart'].value; duration = doc['recordDuration'].value; l = []; for (long i = 0; i \< duration; i += 60000) { l.add(start + i); }; return l;", "field":null, "lang": "groovy" } I get the following request "aggs": { "2": { "date\_histogram": { "field": null, "interval": "minute", "pre\_zone": "+02:00", "pre\_zone\_adjust\_large…

Your script should be simpler, like the `"doc['views'].value.length" ` script of the first link.

Let me know if this helps.

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:56pm UTC](https://discuss.elastic.co/t/search-based-on-variables-count/47004/5 "2017-07-06T13:56:20Z")

</div>


