# Distinct count with filter

**URL:** <https://discuss.elastic.co/t/distinct-count-with-filter/155795>\
**Category:** Elasticsearch\
**Created:** [November 7, 2018, 9:03pm UTC](https://discuss.elastic.co/t/distinct-count-with-filter/155795 "2018-11-07T21:03:50Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [November 9, 2018, 10:34am UTC](https://discuss.elastic.co/t/distinct-count-with-filter/155795/2 "2018-11-09T10:34:08Z")

</div>

As you indicate, Logstash has some features to join related documents in the ingest stream.

Another general approach is to land the events in the index first and then use a job to periodically (every few seconds?) update a separate "session" index with the latest recorded activities in the event index.  
See: "[entity-centric indexing](https://twitter.com/elasticmark/status/1009380268409610240)".

---

_[View the full topic](https://discuss.elastic.co/t/distinct-count-with-filter/155795)._
