# Show my user details in a table

**URL:** <https://discuss.elastic.co/t/show-my-user-details-in-a-table/172037>\
**Category:** Kibana\
**Created:** [March 12, 2019, 11:04pm UTC](https://discuss.elastic.co/t/show-my-user-details-in-a-table/172037 "2019-03-12T23:04:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [March 12, 2019, 11:04pm UTC](https://discuss.elastic.co/t/show-my-user-details-in-a-table/172037/1 "2019-03-12T23:04:10Z")

</div>

I am new to kibana.  
Elastic stack version 6.6.1  
Currently I have a setup Filebeats --\> Logstash --\> Elastic Search --\> Kibana.

I am using this to parse the IIS access logs.

Since I tried to load the default dashboard which comes from filebeat, but that is not what i am looking for.

I want to show the user details in a table . How can I configure this.

```
**iis.access.user_name.keyword numberof hits pages accessed**
      john 20 20

```

note; Instead of showing iis.access.user\_name.keyword which looks ugly can I define a custom name for this value.

Similaly I also want to create a table

```
iis.access.url.keyword number

/xyz/123 20
/123/xyz 30

```

Attached a sample image. Just wanted to show data similar to this.

 ![Untitled](https://us1.discourse-cdn.com/elastic/original/3X/0/3/0337a0ca21e7f88f2fc02b9c40cfa7ec63696e77.png)

---

<div class="post-metadata">

**Author:** ![joshdover](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshdover/32/42020_2.png) [@joshdover](https://discuss.elastic.co/u/joshdover)\
**Post date:** [March 14, 2019, 9:25pm UTC](https://discuss.elastic.co/t/show-my-user-details-in-a-table/172037/2 "2019-03-14T21:25:12Z")

</div>

The easiest method would be to create a Data Table visualization by going to Visualize \> New ("+" icon) \> Data Table \> Choose your index pattern.

- In the left panel, under Buckets, choose Split Rows
- Under the Aggregations dropdown, choose Terms (you may need to scroll)
- Choose the "iis.access.user\_name.keyword" field in the field dropdown
- Select how many you'd like to display in the "Size" Field
- Hit the "Play" button in the top right of the panel

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [March 14, 2019, 10:53pm UTC](https://discuss.elastic.co/t/show-my-user-details-in-a-table/172037/3 "2019-03-14T22:53:49Z")

</div>

Thank you . I was able to create it. One more question. I am currently getting username in my table. Is there a way to convert the user name to full name by hooking this up with our LDAP server?

---

<div class="post-metadata">

**Author:** ![joshdover](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshdover/32/42020_2.png) [@joshdover](https://discuss.elastic.co/u/joshdover)\
**Post date:** [March 15, 2019, 2:44pm UTC](https://discuss.elastic.co/t/show-my-user-details-in-a-table/172037/4 "2019-03-15T14:44:02Z")

</div>

The most standard way of doing this would be to enrich the data as you index into Elasticsearch. Logstash has a feature called [Lookup Enrichment](https://www.elastic.co/guide/en/logstash/current/lookup-enrichment.html) that allows you to lookup data from an outside service and add it to documents before sending them to Elasticsearch. You could use this to integrate with an LDAP server to lookup user information and then display those added fields in your Kibana visualization.

---

<div class="post-metadata">

**Author:** ![syedsfayaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syedsfayaz/32/46657_2.png) [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Post date:** [March 18, 2019, 5:53am UTC](https://discuss.elastic.co/t/show-my-user-details-in-a-table/172037/5 "2019-03-18T05:53:08Z")

</div>

@joshdover Thank you. Will try it and get back with you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 15, 2019, 5:53am UTC](https://discuss.elastic.co/t/show-my-user-details-in-a-table/172037/6 "2019-04-15T05:53:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
