# Displaying an "id" only if it appears N times in the period

**URL:** <https://discuss.elastic.co/t/displaying-an-id-only-if-it-appears-n-times-in-the-period/119679>\
**Category:** Kibana\
**Created:** [February 13, 2018, 4:50pm UTC](https://discuss.elastic.co/t/displaying-an-id-only-if-it-appears-n-times-in-the-period/119679 "2018-02-13T16:50:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DidierB](https://avatars.discourse-cdn.com/v4/letter/d/ed8c4c/32.png) [@DidierB](https://discuss.elastic.co/u/DidierB)\
**Post date:** [February 13, 2018, 4:50pm UTC](https://discuss.elastic.co/t/displaying-an-id-only-if-it-appears-n-times-in-the-period/119679/1 "2018-02-13T16:50:26Z")

</div>

Hello,

I have a log of events containing API access data like [timestamp, id, other\_informations]. We would like to find some information about it.

We know that we can understand things by watching the amount of request we have from one id during a specified period of time. The problem is that Top X gives thousands of normal id access and inverted top X doesn't help (thousands of "1" connection attempt by an id). The id carnality is tens of millions, a full histogram can't be built.

On the other hand, we know that if we can specify N and M to something like **"show me 1000 ids that appear between N and M times in the period of observation"** we will have the info we need.

Any ideas?

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [February 13, 2018, 8:06pm UTC](https://discuss.elastic.co/t/displaying-an-id-only-if-it-appears-n-times-in-the-period/119679/2 "2018-02-13T20:06:37Z")

</div>

If you're trying put these IDs on a visualization, you could get part of the way there by using a terms aggregation on ID, and then specifying the `min_doc_count` in the advanced JSON config. This will limit the terms on that axis to IDs that meet or exceed some threshold.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4fe951dadf5dca4e8096639b3da684e145d6b38a.png)

Once you do that, you can build up a list of IDs you are interested in and create a filter that limits all data to those IDs.

It is a somewhat manual process, but I think it is as far as Kibana will be able to take you until filters can be based on the results of queries or aggregations (maybe something like [https://github.com/elastic/kibana/issues/16702](https://github.com/elastic/kibana/issues/16702)).

---

<div class="post-metadata">

**Author:** ![DidierB](https://avatars.discourse-cdn.com/v4/letter/d/ed8c4c/32.png) [@DidierB](https://discuss.elastic.co/u/DidierB)\
**Post date:** [February 14, 2018, 9:12am UTC](https://discuss.elastic.co/t/displaying-an-id-only-if-it-appears-n-times-in-the-period/119679/3 "2018-02-14T09:12:33Z")

</div>

> [@spalger](#):
>
> min\_doc\_count

Thanks for your reply. I just learned something 🙂

Since there is no "max\_doc\_count", I have to combine with an ascending sort to have my information and Kibana say this is deprecated.

My next step is entity centric indexing, but it requires scripting skills which I don't have in the context of Elasticsearch. I'll open a separate topic when needed.

Thank you again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2018, 9:12am UTC](https://discuss.elastic.co/t/displaying-an-id-only-if-it-appears-n-times-in-the-period/119679/4 "2018-03-14T09:12:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
