# Counting users that returned to the website

**URL:** <https://discuss.elastic.co/t/counting-users-that-returned-to-the-website/234454>\
**Category:** Elasticsearch\
**Created:** [May 27, 2020, 4:19am UTC](https://discuss.elastic.co/t/counting-users-that-returned-to-the-website/234454 "2020-05-27T04:19:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanjaysubramanian](https://avatars.discourse-cdn.com/v4/letter/s/bcef8e/32.png) [@sanjaysubramanian](https://discuss.elastic.co/u/sanjaysubramanian)\
**Post date:** [May 27, 2020, 4:19am UTC](https://discuss.elastic.co/t/counting-users-that-returned-to-the-website/234454/1 "2020-05-27T04:19:30Z")

</div>

The following is a simplified look at our mappings in Elastic search

```auto
{
    "mappings" : {
        "properties": {
                    "userid": { "type": "keyword" },
                    "yyyy_mm_dd": { "type": "date", "format": "yyyy-MM-dd" },
                    "ts": { "type": "date"}
    }
}

```

**Usecase**  
[eric@cream.com](mailto:eric@cream.com), 2020-03-28, 1585357301265  
[paul@beatles.com](mailto:paul@beatles.com), 2020-03-28, 1585382231269  
[john@beatles.com](mailto:john@beatles.com), 2020-03-28, 1585383569863  
[eric@cream.com](mailto:eric@cream.com), 2020-03-28, 1585414906564

[paul@beatles.com](mailto:paul@beatles.com)), 2020-03-29, 1585466637966  
[ginger@cream.com](mailto:ginger@cream.com), 2020-03-29, 1585493882027  
[george@beatles.com](mailto:george@beatles.com), 2020-03-29, 1585486384984

[paul@beatles.com](mailto:paul@beatles.com), 2020-03-30, 1585562310061  
[jackbruce@cream.com](mailto:jackbruce@cream.com), 2020-03-30, 1585571947493  
[eric@cream.com](mailto:eric@cream.com), 2020-03-30, 1585597746891  
[john@beatles.com](mailto:john@beatles.com), 2020-03-30, 1585555104127  
[ginger@cream.com](mailto:ginger@cream.com), 2020-03-30, 1585563504459  
[freddie@queen.com](mailto:freddie@queen.com), 2020-03-30, 1585578397198

**My desired Visualization for Return Users**

2020-03-28 - 4 return users (timeline starts there)

2020-03-29 - 1 return user (paul)

2020-03-30 - 4 return users. (paul, eric, john and ginger)

---

<div class="post-metadata">

**Author:** ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)\
**Post date:** [May 27, 2020, 7:23am UTC](https://discuss.elastic.co/t/counting-users-that-returned-to-the-website/234454/2 "2020-05-27T07:23:12Z")

</div>

This goes into the same direction as your last [question](https://discuss.elastic.co/t/calculate-daily-new-users-never-seen-before-to-a-website/234404).

Having an entity centric index helps again. If in addition to `min(ts)`, which corresponds to "user first seen" you add a `max(ts)`, which would be "user last seen", you can use a scripted metric to check whether `max - min` is above a threshold you define for "returning user".

---

<div class="post-metadata">

**Author:** ![sanjaysubramanian](https://avatars.discourse-cdn.com/v4/letter/s/bcef8e/32.png) [@sanjaysubramanian](https://discuss.elastic.co/u/sanjaysubramanian)\
**Post date:** [May 27, 2020, 1:37pm UTC](https://discuss.elastic.co/t/counting-users-that-returned-to-the-website/234454/3 "2020-05-27T13:37:27Z")

</div>

Thank you @Hendrik_Muhs  
Could you please provide additional guidance on how to implement a scripted metric?  
thanks  
warmly  
sanjay

---

<div class="post-metadata">

**Author:** ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)\
**Post date:** [May 27, 2020, 5:52pm UTC](https://discuss.elastic.co/t/counting-users-that-returned-to-the-website/234454/4 "2020-05-27T17:52:30Z")

</div>

I thought a bit more about this usecase and realized that I misunderstood it. The suggested `max` to get the last time a user has been seen might be useful, but does not help to chart returned users over time, because it would only give you the last time the user has been seen, but you want all time buckets that a certain user has been seen.

I do not have a solution at hand, but can only provide ideas that might lead to a solution:

- given the user index from the other transform, you could [enrich](https://www.elastic.co/guide/en/elasticsearch/reference/7.7/enrich-processor.html) incoming data with user information, e.g. the first time the user has been seen. That again can be used together with a [scripted field](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html) to decide if the user is a new or old user
- another transform that ceates the histogram already and filters out new users by joining with the user index

Both are very vague ideas, sorry, I can't provide more input.

Having that said, I wonder: With TSVB you could chart the total number of users and the number of new users in 1 chart. The area between the 2 graphs are the returned users. This is not exactly what you are asking for, but transports the same message.

---

<div class="post-metadata">

**Author:** ![sanjaysubramanian](https://avatars.discourse-cdn.com/v4/letter/s/bcef8e/32.png) [@sanjaysubramanian](https://discuss.elastic.co/u/sanjaysubramanian)\
**Post date:** [May 27, 2020, 6:00pm UTC](https://discuss.elastic.co/t/counting-users-that-returned-to-the-website/234454/5 "2020-05-27T18:00:52Z")

</div>

Not at all, these are great ideas I can run with - So a big shout out of THANKS ! 🙂 @Hendrik_Muhs  
That "enrich" fields in index1 from index2 seems promising to delve deeper into for sure

Thanks again ! I really really appreciate (and am grateful to) your alacrity.

warmly

sanjay

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2020, 6:11pm UTC](https://discuss.elastic.co/t/counting-users-that-returned-to-the-website/234454/6 "2020-06-24T18:11:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
