Inspect grouped STATS results in Discover

When your ES|QL query uses a STATS BY clause with a single grouping field, Discover displays the results as expandable groups instead of a flat table. Each row represents one unique value of the grouping field. You can expand it to inspect the underlying documents without leaving the query.

  • You need an ES|QL query in Discover. If you're new to ES|QL in Discover, start with Get started with ES|QL in Discover.
  • Your query groups by a single field, or by a single CATEGORIZE call. Other queries keep the standard flat results table:
    • Queries that group by more than one field, for example BY clientip, extension.keyword.
    • Queries that use other grouping functions, such as BUCKET or TBUCKET.
    • Queries that use TS_INFO or METRICS_INFO. Their rows describe metrics and have no documents to expand.
  1. In Discover, in ES|QL mode, enter a STATS BY query with a single grouping field. For example:

    FROM kibana_sample_data_logs
    | STATS Visits = COUNT(*), AvgBytes = AVG(bytes) BY geo.dest
    | SORT Visits DESC
    		
  2. Select Search.

    Result: The table lists one row per group. The results count reports the number of groups instead of the number of documents.

    Note

    When you search large data sets, you can get faster, estimated results by using Fast mode. Refer to Use ES|QL in the Kibana UI > Get faster results with approximate STATS.

    Grouped results layout in Discover, with one row expanded to show underlying documents
  3. Expand a row to inspect the underlying documents.

When the grouping field uses CATEGORIZE, each row title shows the detected pattern with token highlighting, so you can scan repeated message structures at a glance.

FROM kibana_sample_data_logs
| STATS Count = COUNT(*) BY Pattern = CATEGORIZE(message)
| SORT Count DESC
		
Tip

Pattern detection on text fields is also available outside ES|QL from the Patterns view in Discover's classic mode. Refer to Run a pattern analysis on your log data.

When the query also computes a SPARKLINE over time, Discover renders an inline chart next to the row aggregates. For example, the following query categorizes log messages and renders a sparkline for each pattern:

FROM kibana_sample_data_logs
| WHERE @timestamp >= ?_tstart AND @timestamp < ?_tend
| STATS Count = COUNT(*),
        Sparkline = SPARKLINE(COUNT(*), @timestamp, 40, ?_tstart, ?_tend)
    BY Pattern = CATEGORIZE(message)
| SORT Count DESC
		

On larger data sets, add a SAMPLE command before STATS to keep the categorization fast, and divide COUNT(*) by the same sample fraction to keep the counts representative. For example, SAMPLE 0.001 followed by Count = COUNT(*) / 0.001.

A grouped row showing a CATEGORIZE pattern with token highlighting and an inline sparkline

Select the actions button on any group row to:

  • Copy to clipboard: copy the group's value.
  • Filter in: append a WHERE clause to your query that keeps only documents matching this group.
  • Filter out: append a WHERE clause that excludes documents matching this group.
  • Open in new tab: open the documents in this group in a new Discover tab, with a query scoped to that group.

Filter in and Filter out are disabled when the grouping field isn't filterable.

When the grouped layout activates, Discover replaces the regular results table toolbar with a Group by button. The button shows the number of active groupings as a badge.

Discover preselects the grouping field from your STATS BY clause. From the Group by menu, select none to go back to the standard flat results table and the regular toolbar.