# Use script to filter the logs based on specific value of field

**URL:** <https://discuss.elastic.co/t/use-script-to-filter-the-logs-based-on-specific-value-of-field/217556>\
**Category:** Kibana\
**Created:** [February 3, 2020, 4:41am UTC](https://discuss.elastic.co/t/use-script-to-filter-the-logs-based-on-specific-value-of-field/217556 "2020-02-03T04:41:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Parth\_Kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/parth_kalaria/32/61450_2.png) [@Parth\_Kalaria](https://discuss.elastic.co/u/Parth_Kalaria)\
**Post date:** [February 3, 2020, 4:41am UTC](https://discuss.elastic.co/t/use-script-to-filter-the-logs-based-on-specific-value-of-field/217556/1 "2020-02-03T04:41:12Z")

</div>

Can I add an condition for metrics aggregation on y axis to check for the specific field value. I'm trying to create a bar chart with 2 y axis aggregation. In one aggregation I want count of all the docs and for another aggregation I only want count of logs with specific field value.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/c/2cc108fae75b4b7b0542a49f0ab8bbc44b30ef24.png)

Here For "Total Submission" aggregation I'm taking count of all the logs but for "SonarQube failed checks" aggregation I only want the count of the logs for which the field "name" has the "release\_sonarqube\_check" value. For that I'm using  
{ "script" : "doc['name'].value=release\_sonarqube\_check"} script but it's not even adding in msearch request body. Can someone suggest if it's possible and what might be the correct way to write script for that?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 3, 2020, 5:22pm UTC](https://discuss.elastic.co/t/use-script-to-filter-the-logs-based-on-specific-value-of-field/217556/2 "2020-02-03T17:22:05Z")

</div>

@Hey @Parth_Kalaria, you can use the "JSON Input" to specify a script like the following example, but it won't give you what you're looking for: [https://www.elastic.co/guide/en/elasticsearch/reference/master/search-aggregations-metrics-cardinality-aggregation.html#\_script\_3](https://www.elastic.co/guide/en/elasticsearch/reference/master/search-aggregations-metrics-cardinality-aggregation.html#_script_3)

Instead, I'd recommend using a configuration similar to the following, which doesn't rely on the JSON Input:

 ![Screen Shot 2020-02-03 at 9.19.51 AM](https://us1.discourse-cdn.com/elastic/original/3X/e/e/ee94853069337a26937b8c6d3654e7cc2196eb36.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 5:22pm UTC](https://discuss.elastic.co/t/use-script-to-filter-the-logs-based-on-specific-value-of-field/217556/3 "2020-03-02T17:22:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
