# Filter each bucket based on previous buckets

**URL:** <https://discuss.elastic.co/t/filter-each-bucket-based-on-previous-buckets/165280>\
**Category:** Elasticsearch\
**Created:** [January 22, 2019, 5:52pm UTC](https://discuss.elastic.co/t/filter-each-bucket-based-on-previous-buckets/165280 "2019-01-22T17:52:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wassim\_Ben\_Amor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wassim_ben_amor/32/39799_2.png) [@Wassim\_Ben\_Amor](https://discuss.elastic.co/u/Wassim_Ben_Amor)\
**Post date:** [January 22, 2019, 5:52pm UTC](https://discuss.elastic.co/t/filter-each-bucket-based-on-previous-buckets/165280/1 "2019-01-22T17:52:49Z")

</div>

Hello,  
I have documents representing user requests, each document contains user\_id and timestamp.  
A simple date histogram aggregation generates the number of daily users like this

> {  
> "aggs": {  
> "2": {  
> "date\_histogram": {  
> "field": "@timestamp",  
> "interval": "1d",  
> "min\_doc\_count": 0  
> },  
> "aggs": {  
> "1": {  
> "cardinality": {  
> "field": "user\_id.keyword"  
> }  
> }  
> }  
> }  
> },  
> "size": 0  
> }

This will generate a graph for total daily users.  
I want to make graphs for new users and returning users.  
For new users : Filter the buckets to not count documents which contains user\_id that is already counted in a previous bucket.  
For returning users : Filter the buckets to count only documents which contains user\_id that is already counted in a previous bucket.  
How can I do this ?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [January 22, 2019, 8:04pm UTC](https://discuss.elastic.co/t/filter-each-bucket-based-on-previous-buckets/165280/2 "2019-01-22T20:04:03Z")

</div>

“New users” on an event-centric index ticks all the boxes for problems:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8bfe92aef11d6ca895332500d73885131e0d1bb5.jpeg)

If you create an entity centric index for users which holds the date of the first sighting you can run a “new users” efficiently with a simple date histogram on that firstSighted field.  
To get “returning users” hit your event store with your example query that had cardinalities and subtract the “new users” value for each day (this may require work in your client)

---

<div class="post-metadata">

**Author:** ![Wassim\_Ben\_Amor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wassim_ben_amor/32/39799_2.png) [@Wassim\_Ben\_Amor](https://discuss.elastic.co/u/Wassim_Ben_Amor)\
**Post date:** [January 23, 2019, 9:02am UTC](https://discuss.elastic.co/t/filter-each-bucket-based-on-previous-buckets/165280/3 "2019-01-23T09:02:01Z")

</div>

Thank you for your reply @Mark_Harwood, the entity centric index approach is the solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2019, 9:02am UTC](https://discuss.elastic.co/t/filter-each-bucket-based-on-previous-buckets/165280/4 "2019-02-20T09:02:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
