# Count Of Metric after Doing Top Hits

**URL:** <https://discuss.elastic.co/t/count-of-metric-after-doing-top-hits/169292>\
**Category:** Kibana\
**Created:** [February 20, 2019, 9:19pm UTC](https://discuss.elastic.co/t/count-of-metric-after-doing-top-hits/169292 "2019-02-20T21:19:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![misiakj](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@misiakj](https://discuss.elastic.co/u/misiakj)\
**Post date:** [February 20, 2019, 9:19pm UTC](https://discuss.elastic.co/t/count-of-metric-after-doing-top-hits/169292/1 "2019-02-20T21:19:43Z")

</div>

I have data that looks similar to the following:

(case\_id, create\_date, status)

I want to be able to select the most recent document for each case\_id, and then sum the counts of the different statuses. So if my data looked like the below

case\_id: 1 | create\_date 2019-2-20-00:00:00 | closed  
case\_id: 1 | create\_date 2019-1-20-00:00:00 | working  
case\_id: 1 | create\_date 2019-1-10-00:00:00 | assigned

case\_id: 2 | create\_date 2019-2-10-00:00:00 | closed  
case\_id: 2 | create\_date 2019-1-00-00:00:00 | assigned

case\_id: 3 | create\_date 2019-1-10-00:00:00 | assigned

case\_id: 4 | create\_date 2019-1-20-00:00:00 | working  
case\_id: 4 | create\_date 2019-1-10-00:00:00 | assigned

The results would show

assigned: 1  
working: 1  
closed: 2

I would like to do this in a Kibana visualization, is this possible?  
Below I have uploaded an image where I'm able to get a data table showing the latest status of each ticket, now I just need a "Count" of each of those statuses.

 ![Kibana%20Last%20Status%20Snip](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6df2727b1ec390e02d7bd9afe3b25f17a767afcc.png)

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [February 21, 2019, 9:52pm UTC](https://discuss.elastic.co/t/count-of-metric-after-doing-top-hits/169292/2 "2019-02-21T21:52:12Z")

</div>

The most straightforward and scalable way would be to have an index of data modeled separately. Here, instead of an index of raw events, having a caseId centric index would make this an easy aggregation.

The caseId index would use `case_id` as the \_id for the ES docs. When events come in, update the case document by ID and it will have the latest status.

The table then becomes an aggregation of each status keyword, and the count of documents in the case index that have that status.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2019, 9:52pm UTC](https://discuss.elastic.co/t/count-of-metric-after-doing-top-hits/169292/3 "2019-03-21T21:52:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
