# Tabelle in Vega

**URL:** <https://discuss.elastic.co/t/tabelle-in-vega/268793>\
**Category:** Kibana\
**Created:** [March 30, 2021, 12:53pm UTC](https://discuss.elastic.co/t/tabelle-in-vega/268793 "2021-03-30T12:53:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bab/32/86201_2.png) [@bab](https://discuss.elastic.co/u/bab)\
**Post date:** [March 30, 2021, 12:53pm UTC](https://discuss.elastic.co/t/tabelle-in-vega/268793/1 "2021-03-30T12:53:14Z")

</div>

hello guys,

I have a requirement, looks like this scenario, from a CSV file 5 columns are imported into kibana and the expected visualization of it data is to create kind of table Visia.. where the values of the fields exchange with another, an example.  
Column1 : `Date`  
Column2 : `Start Status`  
_ **`Date`** _ is written in the file as date `12.03.2019 11:23:44`  
_ **`Start Status`** _ is written in the file as text (string) `Start inboud XY`.  
i want to get a visualization which show me die field `Start Status` inside there the value from the other field `Date`, some thing like :

**the input format CSV looks like 1**  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff8d10dc24ed8c97df0d1c4d6b8b60958b3261da.png)

**i want a table visualization looks like 2**  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/f/7ff9e809b0af18a8661ae57bfd6a3d26e7569487.png)

How can I use Vega code or the Table visualization in kibana to create a table that look like the second example above.

Thank you in advance !!

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [March 30, 2021, 6:40pm UTC](https://discuss.elastic.co/t/tabelle-in-vega/268793/2 "2021-03-30T18:40:24Z")

</div>

Your question is a bit confusing, so I am going to try to make some general comments to help you clarify your question:

1. It looks like you haven't created any documents inside Elasticsearch. My expertise is Kibana visualizations, and there are other forums that can help you figure out how to convert CSVs into documents
2. Vega can't build tables. I wish it could, but it's not supported.
3. There are two main types of tables in Kibana: aggregated and non-aggregated.  
a. Discover is non-aggregated, and can be saved onto a dashboard.  
b. Aggregated tables are commonly shown as "detail views" where you use a Terms aggregation for your first column, and then all the metrics are Top Hits/Last Value. "Last value" is a useful concept for many tables
4. I recommend creating tables in Lens, but it can also be done in TSVB and aggregation-based visualizations.
5. There is a third-party table plugin called kibana-enhanced-table that some users prefer

---

<div class="post-metadata">

**Author:** ![bab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bab/32/86201_2.png) [@bab](https://discuss.elastic.co/u/bab)\
**Post date:** [March 31, 2021, 8:30am UTC](https://discuss.elastic.co/t/tabelle-in-vega/268793/3 "2021-03-31T08:30:19Z")

</div>

> [@wylie](#):
>
> plugin called kibana-enhanced-table

so i have already imported my CSV file on my Elasticsearch and split it into single fields/. i started with the Aggregate Tables visualisation and used the metrics Top/hit Last Value, it's ok it delivers the data in a row, that's fine, however i want to see the distribution of the field (`Start and End Date` & `Processing status`) as described in the picture, see below.

how can I use JSON input here for a nested aggregation or something like that, what can you recommend here?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/eedfb7293daf2249e04cfc3d5438e05efb518209.png)

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [March 31, 2021, 2:33pm UTC](https://discuss.elastic.co/t/tabelle-in-vega/268793/4 "2021-03-31T14:33:39Z")

</div>

Can you show me an example document in Discover or the Kibana dev tools?

The JSON input is not relevant here, sorry. I recommend _never_ using it because it is not helpful.

---

<div class="post-metadata">

**Author:** ![bab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bab/32/86201_2.png) [@bab](https://discuss.elastic.co/u/bab)\
**Post date:** [March 31, 2021, 2:58pm UTC](https://discuss.elastic.co/t/tabelle-in-vega/268793/5 "2021-03-31T14:58:45Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/b/3/b3907e41d2ce63dca3c52ec31b5e7908d8829182.png)

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [March 31, 2021, 3:35pm UTC](https://discuss.elastic.co/t/tabelle-in-vega/268793/6 "2021-03-31T15:35:36Z")

</div>

Okay. What you've asked for is "splitting the columns". What you need to do that is to add additional fields to your Kibana index pattern. There are two ways to do this:

1. You can add extra Kibana runtime fields (in 7.12)/scripted fields (older versions). Since you have `Start and End Date` as one field, but want to display it as two fields, you can split this using a Painless script

2. You can use an Elasticsearch ingest pipeline (a built-in feature) to process each document as it is ingested into Elasticsearch. For example, using the [script processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/script-processor.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2021, 3:36pm UTC](https://discuss.elastic.co/t/tabelle-in-vega/268793/7 "2021-04-28T15:36:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
