# Get unique count of most recent event

**URL:** <https://discuss.elastic.co/t/get-unique-count-of-most-recent-event/117712>\
**Category:** Kibana\
**Created:** [January 30, 2018, 10:30pm UTC](https://discuss.elastic.co/t/get-unique-count-of-most-recent-event/117712 "2018-01-30T22:30:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ted\_Jenkins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ted_jenkins/32/27155_2.png) [@Ted\_Jenkins](https://discuss.elastic.co/u/Ted_Jenkins)\
**Post date:** [January 30, 2018, 10:30pm UTC](https://discuss.elastic.co/t/get-unique-count-of-most-recent-event/117712/1 "2018-01-30T22:30:21Z")

</div>

I have several devices, each with a unique id, where each has a field that can change value. I would like to get a count of those objects whose fields equals a particular value.

For example, the foo.bar.wifiStatus field on any number of these devices can be "online". I want to show a total count of which devices are currently that value, and when one of the device's field's changes value, the count gets decremented accordingly.

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [January 31, 2018, 2:16am UTC](https://discuss.elastic.co/t/get-unique-count-of-most-recent-event/117712/2 "2018-01-31T02:16:27Z")

</div>

If I understand what you're looking for correctly, I just responded to a user with something similar.

> [@Scripted Fields in kibana not working](https://discuss.elastic.co/t/scripted-fields-in-kibana-not-working/117661/2):
>
> It's possible to do this with the Time Series Visual Builder I have used the following data to test against: POST discuss-117661/doc { "@timestamp": "2018-01-30T14:25:04", "Return\_Code": 1, "somme": 1 } POST discuss-117661/doc { "@timestamp": "2018-01-30T14:25:04", "Return\_Code": 1, "somme": 1 } POST discuss-117661/doc { "@timestamp": "2018-01-30T14:25:04", "Return\_Code": 1, "somme": 1 } POST discuss-117661/doc { "@timestamp": "2018-01-30T14:25:04", "Return\_Code": 0, …

With the Time Series Visual Builder, you can use the Filter Ratio to create a visualization to show the percentage or count of online/offline devices.

---

<div class="post-metadata">

**Author:** ![Ted\_Jenkins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ted_jenkins/32/27155_2.png) [@Ted\_Jenkins](https://discuss.elastic.co/u/Ted_Jenkins)\
**Post date:** [January 31, 2018, 8:44pm UTC](https://discuss.elastic.co/t/get-unique-count-of-most-recent-event/117712/3 "2018-01-31T20:44:34Z")

</div>

I want the metric to show total online devices of 1 and a total of offline devices of 2 based off the most recent timestamp. In the timeseries builder with the setting on metric, I have this data in an index called wifi\_status with the filter ratio of `foo.bar.wifistatus:online`, the `Denominator: *`, `Metric Aggregation:count`, `Grouped by: everything`. I am getting a count of zero when I am expecting 1.

Example Data:  
{  
"foo.bar.timestamp": "2018-01-30T14:25:10",  
"foo.bar.wifistatus": online,  
"foo.bar.uuid": "0000-0000-0000-1000"  
},  
{  
"foo.bar.timestamp": "2018-01-30T14:25:05",  
"foo.bar.wifistatus": offline,  
"foo.bar.uuid": "0000-0000-0000-1000"  
},  
{  
"foo.bar.timestamp": "2018-01-30T14:25:00",  
"foo.bar.wifistatus": online,  
"foo.bar.foo.uuid": "0000-0000-0000-1000"  
},  
{  
"foo.bar.timestamp": "2018-01-30T14:25:10",  
"foo.bar.wifistatus": offline,  
"foo.bar.uuid": "0000-0000-0000-2000"  
},  
{  
"foo.bar.timestamp": "2018-01-30T14:25:05",  
"foo.bar.wifistatus": online,  
"foo.bar.uuid": "0000-0000-0000-2000"  
},  
{  
"foo.bar.timestamp": "2018-01-30T14:25:10",  
"foo.bar.wifistatus": offline,  
"foo.bar.uuid": "0000-0000-0000-3000"  
},  
{  
"foo.bar.timestamp": "2018-01-30T14:25:05",  
"foo.bar.foo.wifistatus": online,  
"foo.bar.uuid": "0000-0000-0000-3000"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2018, 8:44pm UTC](https://discuss.elastic.co/t/get-unique-count-of-most-recent-event/117712/4 "2018-02-28T20:44:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
