# Getting total count based on collapsed value

**URL:** <https://discuss.elastic.co/t/getting-total-count-based-on-collapsed-value/249358>\
**Category:** Elasticsearch\
**Created:** [September 21, 2020, 12:39pm UTC](https://discuss.elastic.co/t/getting-total-count-based-on-collapsed-value/249358 "2020-09-21T12:39:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohanaprakash](https://avatars.discourse-cdn.com/v4/letter/m/c6cbf5/32.png) [@mohanaprakash](https://discuss.elastic.co/u/mohanaprakash)\
**Post date:** [September 21, 2020, 12:39pm UTC](https://discuss.elastic.co/t/getting-total-count-based-on-collapsed-value/249358/1 "2020-09-21T12:39:22Z")

</div>

I am new to elastic search and i am trying to extract total number of concurrent users active in the given period.

For example i have a data as below

| User | Login Time | Logout Time |
| --- | --- | --- |
| A | 2020-09-21T10:00:00 | 2020-09-21T10:30:00 |
| B | 2020-09-21T10:00:10 | 2020-09-21T10:30:15 |
| C | 2020-09-21T10:00:08 | 2020-09-21T10:30:10 |
| D | 2020-09-21T10:00:15 | 2020-09-21T10:30:03 |

From the above data i want to build below result

| Time stamp | Concurrent Users |
| --- | --- |
| 2020-09-21T10:00:00 | 1 |
| 2020-09-21T10:00:08 | 2 |
| 2020-09-21T10:00:10 | 3 |
| 2020-09-21T10:00:15 | 4 |
| 2020-09-21T10:30:00 | 4 |
| 2020-09-21T10:30:03 | 3 |
| 2020-09-21T10:30:10 | 2 |
| 2020-09-21T10:30:15 | 1 |

My understanding is we can do this in two steps

1. Extract unique login and logout time
2. \_count the value based on filter (logout time lte given time, login time gte given time)

I would like to know is it possible to extract the result in single query?  
I am working in version 7.9.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2020, 12:39pm UTC](https://discuss.elastic.co/t/getting-total-count-based-on-collapsed-value/249358/2 "2020-10-19T12:39:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
