# Visualization with conditional aggregation

**URL:** <https://discuss.elastic.co/t/visualization-with-conditional-aggregation/206142>\
**Category:** Kibana\
**Created:** [November 1, 2019, 10:16am UTC](https://discuss.elastic.co/t/visualization-with-conditional-aggregation/206142 "2019-11-01T10:16:44Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![earthpatipon](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@earthpatipon](https://discuss.elastic.co/u/earthpatipon)\
**Post date:** [November 1, 2019, 10:16am UTC](https://discuss.elastic.co/t/visualization-with-conditional-aggregation/206142/1 "2019-11-01T10:16:44Z")

</div>

Hi there,

Let's say I define the index like below

```
PUT my_index/_doc/1
{
  "user": [
    {
      "first": "John",
      "last": "Frank"
    },
    {
      "first": "Hero",
      "last": "Tim"
    }
  ]
}

PUT my_index/_doc/2
{
  "user": [
    {
      "firstName": "John",
      "lastName": "Term"
    },
    {
      "firstName": "David",
      "lastName": "Gayle"
    }
  ]
}

```

If I want to list all the user surname whose firstName is John in Data Table visualization, is there a way to accomplish this?

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [November 1, 2019, 2:10pm UTC](https://discuss.elastic.co/t/visualization-with-conditional-aggregation/206142/2 "2019-11-01T14:10:00Z")

</div>

Kibana does not support nested objects yet, [https://www.elastic.co/guide/en/kibana/current/nested-objects.html](https://www.elastic.co/guide/en/kibana/current/nested-objects.html).

I would recommend indexing your data in a flatter structure like below.

```auto
PUT my_index/_doc/1
{
  "user": {
      "first": "John",
      "last": "Frank"
    }
}

PUT my_index/_doc/2
{
  "user": {
      "first": "Hero",
      "last": "Tim"
    }
}

```

---

<div class="post-metadata">

**Author:** ![earthpatipon](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@earthpatipon](https://discuss.elastic.co/u/earthpatipon)\
**Post date:** [November 2, 2019, 11:29am UTC](https://discuss.elastic.co/t/visualization-with-conditional-aggregation/206142/3 "2019-11-02T11:29:29Z")

</div>

Thanks for the reply, Nathan\_Reese

Currently, these logs come from other services which are in nested object. Hence, If I want to modify the log to be flatter structure like you mentioned (for example, create a new log for each user in order to be aggregatable), does Elasticsearch support it?

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [November 2, 2019, 2:21pm UTC](https://discuss.elastic.co/t/visualization-with-conditional-aggregation/206142/4 "2019-11-02T14:21:30Z")

</div>

How are your logs getting ingested into Elasticsearch?

Try using [ingest node](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html) to pre-process documents before indexing

---

<div class="post-metadata">

**Author:** ![earthpatipon](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@earthpatipon](https://discuss.elastic.co/u/earthpatipon)\
**Post date:** [November 2, 2019, 2:32pm UTC](https://discuss.elastic.co/t/visualization-with-conditional-aggregation/206142/5 "2019-11-02T14:32:02Z")

</div>

Yes, I currently use the ingest node to manipulate logs. The log structure before ingested is liked I mentioned above

```
"user": [
    {
      "first": "John",
      "last": "Frank"
    },
    {
      "first": "Hero",
      "last": "Tim"
    }
  ]

```

in a single document  
So, can ingest node do like creating new documents from receiving logs  
for ex. spliting user array into two new documents as you mentioned

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [November 2, 2019, 5:20pm UTC](https://discuss.elastic.co/t/visualization-with-conditional-aggregation/206142/6 "2019-11-02T17:20:45Z")

</div>

yes, you should be able to manipulate the document with ingest node, see documentation for details

---

<div class="post-metadata">

**Author:** ![earthpatipon](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@earthpatipon](https://discuss.elastic.co/u/earthpatipon)\
**Post date:** [November 4, 2019, 5:18am UTC](https://discuss.elastic.co/t/visualization-with-conditional-aggregation/206142/7 "2019-11-04T05:18:49Z")

</div>

I have read it. I found only Set Processor that's more likely to manipulate logs, but it's not what I want. I want to create new document while the data is processing in ingest node. Could you please point out how to do so?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 2, 2019, 5:18am UTC](https://discuss.elastic.co/t/visualization-with-conditional-aggregation/206142/8 "2019-12-02T05:18:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
