# Filter for using a unique value regardless of date

**URL:** <https://discuss.elastic.co/t/filter-for-using-a-unique-value-regardless-of-date/298790>\
**Category:** Kibana\
**Created:** [March 3, 2022, 8:33pm UTC](https://discuss.elastic.co/t/filter-for-using-a-unique-value-regardless-of-date/298790 "2022-03-03T20:33:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pball](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@pball](https://discuss.elastic.co/u/pball)\
**Post date:** [March 3, 2022, 8:33pm UTC](https://discuss.elastic.co/t/filter-for-using-a-unique-value-regardless-of-date/298790/1 "2022-03-03T20:33:08Z")

</div>

Hi All, I have searched and read many articles but have not found an answer or post which matches my criteria.

This is a very simplistic example but I hope it makes it clear. I have 5 users and 3 bats. The green bat has a problem so I need to filter out the users who only only ever use the green bat, in this sample it would be Ryan and Susie, regardless of of date.

Example data:  
|Date|User|Bat Used|  
|1/5/2020|Bob|blue bat|  
|1/5/2020|Joe|blue bat|  
|1/5/2020|Sally|red bat|  
|1/5/2020|Susie|green bat|  
|1/5/2020|Ryan|green bat|  
|1/6/2020|Bob|red bat|  
|1/6/2020|Joe|red bat|  
|1/6/2020|Sally|red bat|  
|1/6/2020|Susie|green bat|  
|1/6/2020|Ryan|green bat|  
|1/7/2020|Bob|blue bat|  
|1/7/2020|Joe|blue bat|  
|1/7/2020|Sally|red bat|  
|1/7/2020|Susie|green bat|  
|1/7/2020|Ryan|green bat|  
|1/8/2020|Bob|blue bat|  
|1/8/2020|Joe|green bat|  
|1/8/2020|Sally|green bat|  
|1/8/2020|Susie|green bat|  
|1/8/2020|Ryan|green bat|

I created a data table and with users for rows and I can set the columns to show the unique count of bat used - Bob and Sally = 2, Joe = 3, and Ryan and Susie = 1. I also tried column filters by bat which is correct but when I try to filter just for the green bat, I also get Joe and Sally who don't meet the criteria as they also used other bats.

How can I isolate just Ryan and Susie? I don't have the timestamp in the visualization but I should come up with a count of 2.

Thanks for the help!

---

<div class="post-metadata">

**Author:** ![Adriann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adriann/32/77780_2.png) [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Post date:** [March 3, 2022, 9:57pm UTC](https://discuss.elastic.co/t/filter-for-using-a-unique-value-regardless-of-date/298790/2 "2022-03-03T21:57:53Z")

</div>

I guess with some fancy coding you could use a script field(It will be deprecated in some new versions in fewer of the runtime field if I remember correctly). You can also look at ingest pipeline script processor and runtime field.

This is an example of a script field that I needed for displaying time for uptime in a way I wanted it.

```auto
String val = "system.uptime.duration.ms";

if (doc[val] != null){ 

    if (doc[val].size() != 0 ){

        long now = doc["@timestamp"].value.toInstant().toEpochMilli();

        long elapsedTime = now - doc['system.uptime.duration.ms'].value;

        return elapsedTime;
    }
}

```

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/f/dfee691469ed65e59b6f1db3200f0a2640d33d19.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2022, 9:58pm UTC](https://discuss.elastic.co/t/filter-for-using-a-unique-value-regardless-of-date/298790/3 "2022-03-31T21:58:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
