# Follow a huge list of customer with kibana ML

**URL:** <https://discuss.elastic.co/t/follow-a-huge-list-of-customer-with-kibana-ml/240395>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [July 8, 2020, 4:07pm UTC](https://discuss.elastic.co/t/follow-a-huge-list-of-customer-with-kibana-ml/240395 "2020-07-08T16:07:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![AmS](https://avatars.discourse-cdn.com/v4/letter/a/a4c791/32.png) [@AmS](https://discuss.elastic.co/u/AmS)\
**Post date:** [July 8, 2020, 4:07pm UTC](https://discuss.elastic.co/t/follow-a-huge-list-of-customer-with-kibana-ml/240395/1 "2020-07-08T16:07:23Z")

</div>

Hello,

I would like to follow a specific list of customers defined by ip address.

For our application deployment we do this in a number of steps like beta (which may concern more than 1000 customers).

I would like to do anomaly detection over the kibana ML plugin for these beta customer

But when I set a list of ip addresses (more than 1000) kibana is blocked.

Is it possible to follow a spécific huge list of customers ?

I m using kibana 7.3

Regards

AmS

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 8, 2020, 5:37pm UTC](https://discuss.elastic.co/t/follow-a-huge-list-of-customer-with-kibana-ml/240395/2 "2020-07-08T17:37:15Z")

</div>

If I understand your question correctly, you want Kibana to build a filtered query with more than 1000 terms - you're right, that could be messy.

Perhaps a more manageable approach would be to enrich your customers index with a new field, for example `beta` such that the value of that field for a particular customer was either `true` or `false`.

If you want to be fancy and dynamically enrich the data at ingest, you could use a separate index to list your beta users, and use the [enrich ingest processor](https://www.elastic.co/blog/introducing-the-enrich-processor-for-elasticsearch-ingest-nodes) to mark that customer as beta user as the data gets ingested.

Then, you can simply run a single term query in kibana (`beta:true`)

---

<div class="post-metadata">

**Author:** ![AmS](https://avatars.discourse-cdn.com/v4/letter/a/a4c791/32.png) [@AmS](https://discuss.elastic.co/u/AmS)\
**Post date:** [July 21, 2020, 2:36pm UTC](https://discuss.elastic.co/t/follow-a-huge-list-of-customer-with-kibana-ml/240395/3 "2020-07-21T14:36:20Z")

</div>

Hi Rich,  
Thanks for your answer.  
adding a new field is a good idea if it is static list of customers.  
My problem is that list is randomly generated for each new version. so i know this list only when deployed on the beta.  
Regards  
AmS

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 21, 2020, 7:10pm UTC](https://discuss.elastic.co/t/follow-a-huge-list-of-customer-with-kibana-ml/240395/4 "2020-07-21T19:10:05Z")

</div>

Ok, maybe I don't fully understand your use-case then. You won't know who the beta users are? Why can't you dynamically create the list of beta users into the lookup index at deployment time?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2020, 7:10pm UTC](https://discuss.elastic.co/t/follow-a-huge-list-of-customer-with-kibana-ml/240395/5 "2020-08-18T19:10:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
