# Complicated filter/aggregation based on an ID excluding CREARED from REVIEVED alerts

**URL:** https://discuss.elastic.co/t/complicated-filter-aggregation-based-on-an-id-excluding-creared-from-revieved-alerts/35882
**Category:** Kibana
**Created:** [November 30, 2015, 10:46am UTC](https://discuss.elastic.co/t/complicated-filter-aggregation-based-on-an-id-excluding-creared-from-revieved-alerts/35882 "2015-11-30T10:46:33Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [November 30, 2015, 12:03pm UTC](https://discuss.elastic.co/t/complicated-filter-aggregation-based-on-an-id-excluding-creared-from-revieved-alerts/35882/2 "2015-11-30T12:03:20Z")

</div>

The most performant and scalable way to do this is possibly through a separate entity-centric alert index. Please see [this post](https://discuss.elastic.co/t/bucket-selector-aggregation-script-access-doc-index-field-value/35516) for further details with respect to a seemingly very similar scenario.

---

_[View the full topic](https://discuss.elastic.co/t/complicated-filter-aggregation-based-on-an-id-excluding-creared-from-revieved-alerts/35882)._
