# Help on a query with dev tools

**URL:** <https://discuss.elastic.co/t/help-on-a-query-with-dev-tools/190282>\
**Category:** Kibana\
**Created:** [July 12, 2019, 4:52pm UTC](https://discuss.elastic.co/t/help-on-a-query-with-dev-tools/190282 "2019-07-12T16:52:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pierre-Philippe](https://avatars.discourse-cdn.com/v4/letter/p/e19b73/32.png) [@Pierre-Philippe](https://discuss.elastic.co/u/Pierre-Philippe)\
**Post date:** [July 12, 2019, 4:52pm UTC](https://discuss.elastic.co/t/help-on-a-query-with-dev-tools/190282/1 "2019-07-12T16:52:20Z")

</div>

Hi there, I'm trying to get the first occurence of the logs containing a given {user\_uuid + user\_agent}, the objective being to retrieve the my users' user\_agent (both platform and string) at the time of the first connexion.  
I tried to do it using data tables visualization but the most precise time interval with this tool is too broad (it says : "This interval creates too many buckets to show in the selected time range, so it has been scaled to 3 hours), which prevents me from identifying logs associated to the account creation (the relevant log is mixed with other logs from the same time interval).  
I think running a query using dev tools is the good way to proceed, but we don't have good experience with queries on Kibana I'm affraid... Would someone have an idea regarding the query I should run ?

FYI, here is a more concrete explanation of what I'm looking for :  
 ![Capture%20d%E2%80%99%C3%A9cran%20de%202019-07-12%2016-15-39](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d4a70bde28e34da5ad093858775c3d983f843e16.png)

Thanks a lot in advance for your help !

Cheers,

Pierre-Philippe

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [July 12, 2019, 8:29pm UTC](https://discuss.elastic.co/t/help-on-a-query-with-dev-tools/190282/2 "2019-07-12T20:29:55Z")

</div>

hi @Pierre-Philippe

Use a top-hits aggregation [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-top-hits-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-top-hits-aggregation.html)

It's supported by a lot of visualizations, e.g. you can create a datatable or metric for the top-hit you are interested in.

---

<div class="post-metadata">

**Author:** ![Pierre-Philippe](https://avatars.discourse-cdn.com/v4/letter/p/e19b73/32.png) [@Pierre-Philippe](https://discuss.elastic.co/u/Pierre-Philippe)\
**Post date:** [July 22, 2019, 5:37pm UTC](https://discuss.elastic.co/t/help-on-a-query-with-dev-tools/190282/3 "2019-07-22T17:37:09Z")

</div>

Hey Thomas,

Thanks a lot for your answer. I must admit I looked at the visualization options but I didn't find it in he drop-down menu so I guess you really have to use code to use that kind of aggregation. Nevertheless, I eventually manage to get the level of details I was looking for by tightening the period of study so I'm all good now.

Thanks for your help anyway !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2019, 5:37pm UTC](https://discuss.elastic.co/t/help-on-a-query-with-dev-tools/190282/4 "2019-08-19T17:37:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
