# Using where filter with multi values field on data table

**URL:** <https://discuss.elastic.co/t/using-where-filter-with-multi-values-field-on-data-table/285498>\
**Category:** Elasticsearch\
**Created:** [September 29, 2021, 5:30pm UTC](https://discuss.elastic.co/t/using-where-filter-with-multi-values-field-on-data-table/285498 "2021-09-29T17:30:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ishu](https://avatars.discourse-cdn.com/v4/letter/i/c4cdca/32.png) [@ishu](https://discuss.elastic.co/u/ishu)\
**Post date:** [September 29, 2021, 5:30pm UTC](https://discuss.elastic.co/t/using-where-filter-with-multi-values-field-on-data-table/285498/1 "2021-09-29T17:30:23Z")

</div>

Hello,

I used to work on Splunk and working with multi values field, and it's easy break multivalue fields using "stats x by xx" command and perform a where filter after.

We considered this log with multi values field :  
{ "multivaluefield" : ["toto","kiki","123"] }

Ex of the Splunk Query :

```auto
| index="test"
| stats c by multivaluefield
| where multivaluefield="toto"

```

The splunk result will only return "toto" value.

Instead of ELK, i perform split using data table then Buckets --\> split rows by multivaluefield.  
I tried to combine using query dsl to only filter on "toto" value :

{  
"query": {  
"bool": {  
"must": [  
{  
"regexp": {  
"multivaluefield": "toto"  
}  
}  
]  
}  
}  
}

But, elk returned all result of my multi value field ☹

 ![elk](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a96213eecf9d78f4922b562a5ab15ff01d6b1232.png)

How i can perfom the same behavior of Splunk on ELK ?

Regards,  
Ishu

---

<div class="post-metadata">

**Author:** ![ishu](https://avatars.discourse-cdn.com/v4/letter/i/c4cdca/32.png) [@ishu](https://discuss.elastic.co/u/ishu)\
**Post date:** [September 30, 2021, 9:07am UTC](https://discuss.elastic.co/t/using-where-filter-with-multi-values-field-on-data-table/285498/2 "2021-09-30T09:07:44Z")

</div>

🆙 ☹

---

<div class="post-metadata">

**Author:** ![ishu](https://avatars.discourse-cdn.com/v4/letter/i/c4cdca/32.png) [@ishu](https://discuss.elastic.co/u/ishu)\
**Post date:** [October 12, 2021, 12:17pm UTC](https://discuss.elastic.co/t/using-where-filter-with-multi-values-field-on-data-table/285498/3 "2021-10-12T12:17:41Z")

</div>

🆙 ☹

---

<div class="post-metadata">

**Author:** ![ishu](https://avatars.discourse-cdn.com/v4/letter/i/c4cdca/32.png) [@ishu](https://discuss.elastic.co/u/ishu)\
**Post date:** [October 28, 2021, 2:32pm UTC](https://discuss.elastic.co/t/using-where-filter-with-multi-values-field-on-data-table/285498/4 "2021-10-28T14:32:29Z")

</div>

🆙 :::

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 25, 2021, 2:32pm UTC](https://discuss.elastic.co/t/using-where-filter-with-multi-values-field-on-data-table/285498/5 "2021-11-25T14:32:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
