# Group by the incoming records and return a list of records with specific event occurred

**URL:** <https://discuss.elastic.co/t/group-by-the-incoming-records-and-return-a-list-of-records-with-specific-event-occurred/242385>\
**Category:** Kibana\
**Created:** [July 23, 2020, 6:19pm UTC](https://discuss.elastic.co/t/group-by-the-incoming-records-and-return-a-list-of-records-with-specific-event-occurred/242385 "2020-07-23T18:19:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nisargtest1](https://avatars.discourse-cdn.com/v4/letter/n/a87d85/32.png) [@nisargtest1](https://discuss.elastic.co/u/nisargtest1)\
**Post date:** [July 23, 2020, 6:19pm UTC](https://discuss.elastic.co/t/group-by-the-incoming-records-and-return-a-list-of-records-with-specific-event-occurred/242385/1 "2020-07-23T18:19:49Z")

</div>

There is one field called "identity\_number" and I am taking 30 days data as input and I need to make a list of group having same identity\_number and then in each group, I need compare the price of most recent identy\_number and mean of price of rest of the identity number and need to list all the identity\_number which has price difference more than double.

e.g. I have 10,000 records in Kibana in last 30 days and I got 2 such groups.  
1 group with 10 same identity\_number and 2nd group with 8 same identity\_number.

for the first group, price of most recent identity number is 100. and mean of price of rest of the 9 identity\_number is 60, then skip this group, do nothing.

for the second group, price of most recent identity number is 100. and mean of price of rest of the 4 identity\_number is 40,which is (100 \> 200% (40) ) then list this identity\_number.

So, is ihere any possible way to achieve this functinality in Kibana. If so, please let me know the way in brief.

Thank you so much in advance.

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [August 13, 2020, 10:21am UTC](https://discuss.elastic.co/t/group-by-the-incoming-records-and-return-a-list-of-records-with-specific-event-occurred/242385/2 "2020-08-13T10:21:56Z")

</div>

Hi @nisargtest1  
I think the best way to achieve this at the moment is using Vega that provides you a more extended way to compute and transform your data: [https://vega.github.io/vega-lite/docs/calculate.html](https://vega.github.io/vega-lite/docs/calculate.html)  
However, vega is not meant to render text in tabular/list form in the same way HTML table and list are conceived. It definitely can render text but you have to adapt a bit the output to your needs (this somehow resable a table and can maybe adapted to your case: [https://vega.github.io/vega-lite/examples/layer\_text\_heatmap.html](https://vega.github.io/vega-lite/examples/layer_text_heatmap.html))  
or you can render an horizontal bar chart with these filtered identity\_numbers and their price means

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2020, 10:21am UTC](https://discuss.elastic.co/t/group-by-the-incoming-records-and-return-a-list-of-records-with-specific-event-occurred/242385/3 "2020-09-10T10:21:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
