# Distinct Report based on 2 columns (Text Field )

**URL:** <https://discuss.elastic.co/t/distinct-report-based-on-2-columns-text-field/270143>\
**Category:** Kibana\
**Created:** [April 14, 2021, 8:00pm UTC](https://discuss.elastic.co/t/distinct-report-based-on-2-columns-text-field/270143 "2021-04-14T20:00:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Showman](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@Showman](https://discuss.elastic.co/u/Showman)\
**Post date:** [April 14, 2021, 8:00pm UTC](https://discuss.elastic.co/t/distinct-report-based-on-2-columns-text-field/270143/1 "2021-04-14T20:00:49Z")

</div>

Hello,  
am new to kibana & elastic  
am trying to get a simple report from a table that has different status for the same Refrence id as Follows:

''''''  
{  
"took": 0,  
"timed\_out": false,  
"\_shards": {  
"total": 1,  
"successful": 1,  
"skipped": 0,  
"failed": 0  
},  
"hits": {  
"total": 6,  
"max\_score": 1,  
"hits": [  
{  
"\_index": "trial14042021",  
"\_type": "\_doc",  
"\_id": "0",  
"\_score": 1,  
"\_source": {  
"User Reference": 1,  
"Status": "Failed"  
}  
},  
{  
"\_index": "trial14042021",  
"\_type": "\_doc",  
"\_id": "1",  
"\_score": 1,  
"\_source": {  
"User Reference": 1,  
"Status": "Failed"  
}  
},  
{  
"\_index": "trial14042021",  
"\_type": "\_doc",  
"\_id": "2",  
"\_score": 1,  
"\_source": {  
"User Reference": 1,  
"Status": "Successful"  
}  
},  
{  
"\_index": "trial14042021",  
"\_type": "\_doc",  
"\_id": "3",  
"\_score": 1,  
"\_source": {  
"User Reference": 2,  
"Status": "Successful"  
}  
},  
{  
"\_index": "trial14042021",  
"\_type": "\_doc",  
"\_id": "4",  
"\_score": 1,  
"\_source": {  
"User Reference": 3,  
"Status": "Failed"  
}  
},  
{  
"\_index": "trial14042021",  
"\_type": "\_doc",  
"\_id": "5",  
"\_score": 1,  
"\_source": {  
"User Reference": 3,  
"Status": "Failed"  
}  
}  
]  
}  
}  
'''''''''''''''''''  
What i need to do is to get the result of 1 failed User Reference & 2 successful,

while using Kibana visualization it shows 2 failed & 2 successful,  
Any one can support  
this is the mapping of the index  
'''''''''''''''''  
{  
"trial14042021": {  
"mappings": {  
"\_doc": {  
"properties": {  
"Status": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"User Reference": {  
"type": "long"

 ![Kibana](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b52a9f9da32f538e8ed6e842f7e90d6454f72d80.png)  
}  
}  
}  
}  
}  
}

''''''''''''''''

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [April 15, 2021, 12:00am UTC](https://discuss.elastic.co/t/distinct-report-based-on-2-columns-text-field/270143/2 "2021-04-15T00:00:57Z")

</div>

Can you say what is the logic?  
Thanks

---

<div class="post-metadata">

**Author:** ![Showman](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@Showman](https://discuss.elastic.co/u/Showman)\
**Post date:** [April 15, 2021, 9:02am UTC](https://discuss.elastic.co/t/distinct-report-based-on-2-columns-text-field/270143/3 "2021-04-15T09:02:24Z")

</div>

Hello Clerk,

The logic is that i have 3 items processed,  
The 1st one has retried 3 times, the first 2 runs Status failed & the 3rd run Status successes,  
The 2nd ticket Status is Success  
the 3rd ticket Status is retried twice & both Failed.

so what i need is to have the final report  
Total unique count ticket is 3  
Total Success is 2  
Total Failed is 1  
but what actually got is  
Total unique count ticket is 3  
Total Success is 2  
Total Failed is 2

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [April 16, 2021, 1:05am UTC](https://discuss.elastic.co/t/distinct-report-based-on-2-columns-text-field/270143/4 "2021-04-16T01:05:25Z")

</div>

Try using [top hits aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-top-hits-aggregation.html).  
That will give you the last status of each document.  
Cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2021, 1:05am UTC](https://discuss.elastic.co/t/distinct-report-based-on-2-columns-text-field/270143/5 "2021-05-14T01:05:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
