# Update kibana filters using values from a different field

**URL:** <https://discuss.elastic.co/t/update-kibana-filters-using-values-from-a-different-field/156717>\
**Category:** Kibana\
**Created:** [November 14, 2018, 5:04pm UTC](https://discuss.elastic.co/t/update-kibana-filters-using-values-from-a-different-field/156717 "2018-11-14T17:04:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![edovac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edovac/32/51310_2.png) [@edovac](https://discuss.elastic.co/u/edovac)\
**Post date:** [November 14, 2018, 5:04pm UTC](https://discuss.elastic.co/t/update-kibana-filters-using-values-from-a-different-field/156717/1 "2018-11-14T17:04:02Z")

</div>

Hi,  
I'm using the ELK stack to do some performance monitoring on java methods inside my app. I'm also trying to do some execution time profiling. Thus, I'm storing events in which I have current method name and also some stack trace in form of a path.

ELK stack version: 6.4.1

I'm storing events of this kind for first level methods' calls:

```
{
	"@timestamp": "2018-11-14 14:55:40,674",
	"message": {
		"current": "iecsmas.Service4Test.doSomething",
		"parent": {
			"path": "null",
			"success": true
		},
		"executionTime": [40],
		"executionTimeSum": 40,
		"samples": 1,
		"success": true,
		"eventType": "apiMonitor"
	}
}

```

where:

- _parent.path_ is always null
- _current_ is current method name (with shortened package name and full class name)

The same event is also used to store callee informations (when available).  
The same model can assume these values for callee methods:

```
{
	"@timestamp": "2018-11-14 14:55:40,690",
	"message": {
		"current": "iecsmas.SubService4Test.doSomethingCorrect",
		"parent": {
			"path": "iecsmas.Service4Test.doSomething",
			"success": true
		},
		"executionTime": [16, 8],
		"executionTimeSum": 24,
		"samples": 2,
		"success": true,
		"eventType": "apiMonitor"
	}
}

```

where:

- _parent.path_ is the caller method or a path o caller methods (with shortened package name and full class name)
- _current_ is current method name (with shortened package name and full class name)

As you can see, the second event is a callee of the first event.  
I'm taking in account multiple callee invocations in the same caller execution, within the array of executionTime.

Now, I'm trying to build a dashboard to show single methods' trends and enable some drill down.  
First visualization is something like a pie for topmost called methods, usually on first level (ie. with parent.path = null). This should be easily done with a filter on _parent.path_ field and a pie on a terms aggregation on _current_ field.  
What I'm failing to achieve is to update _parent.path_ filter by clicking on a pie slice, since slices are populated with _current_ field values. Moreover, for a further drill down I would like to combine _parent.path_ value with _current_ value.

Filter values should be as follow:

First call:

- parent.path = null

Second call, after clicking on _iecsmas.Service4Test.doSomething_ slice

- parent.path = iecsmas.Service4Test.doSomething

Thirc call, after clicking on _iecsmas.SubService4Test.doSomethingCorrect_

- parent.path = iecsmas.Service4Test.doSomething/iecsmas.SubService4Test.doSomethingCorrect

Is it possible to apply a calculated value in a field filter?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2018, 5:04pm UTC](https://discuss.elastic.co/t/update-kibana-filters-using-values-from-a-different-field/156717/2 "2018-12-12T17:04:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
