# Help on a special visualisation

**URL:** <https://discuss.elastic.co/t/help-on-a-special-visualisation/147075>\
**Category:** Kibana\
**Created:** [September 3, 2018, 12:31pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075 "2018-09-03T12:31:34Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![CryptArks](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CryptArks](https://discuss.elastic.co/u/CryptArks)\
**Post date:** [September 3, 2018, 12:31pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/1 "2018-09-03T12:31:34Z")

</div>

Hello everyone,  
I'm having troubles looking for a unique count formula.  
Here's how my data is working :

```
PUT /general
{
  "mappings": {
    "events": {
      "properties": {
        "type": {
          "type": "keyword"
        },
        "address": {
          "type": "keyword"
        },

```

My type has multiple events, and i'm looking for type : "created"  
If I hit on discover on kibana type : created, I'll have all my created types.  
I want to show a unique count having the type:"created" with a unique address.

So I tried a filter in discover under the type:created such as :

```
{
"size": 0,
 "aggs": {
   "uniqueValueCount": {
     "cardinality": {
       "field": "mappings.events.address.keyword"
     }} }} 

```

But well it's not working, i'm totally new at this any help would be greatly welcome

Thanks!

---

<div class="post-metadata">

**Author:** ![CryptArks](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CryptArks](https://discuss.elastic.co/u/CryptArks)\
**Post date:** [September 4, 2018, 7:56am UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/2 "2018-09-04T07:56:04Z")

</div>

Anyone can help? 🙂

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [September 4, 2018, 12:32pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/3 "2018-09-04T12:32:21Z")

</div>

Hey @CryptArks, would you mind describing the final output that you're looking to generate? Are you looking for a table of unique addresses with their count which also have `type: created`?

---

<div class="post-metadata">

**Author:** ![CryptArks](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CryptArks](https://discuss.elastic.co/u/CryptArks)\
**Post date:** [September 5, 2018, 12:26pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/4 "2018-09-05T12:26:58Z")

</div>

Hi @Brandon_Kobel,  
Thank you very much for your help,  
Exactly, the other way around, i'm looking for a count (or table) about :  
`type:created and unique addresses`

So counting all the type:created that have unique addresses, and add this count to my dashboard.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [September 5, 2018, 4:29pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/5 "2018-09-05T16:29:49Z")

</div>

Hey @CryptArks, it sounds like the Data Table Visualization is what you're looking for with a terms aggregation.

---

<div class="post-metadata">

**Author:** ![CryptArks](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CryptArks](https://discuss.elastic.co/u/CryptArks)\
**Post date:** [September 5, 2018, 5:11pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/6 "2018-09-05T17:11:07Z")

</div>

Hi @Brandon_Kobel  
Yes that's exactly what i tried to do.  
To do the visualization i tried 2 things :  
1st : On discover filter by type:created and add a filter in querydsl with the aggregation i tried to do on top. The code didn't work so i got stucked.  
2nd : I saved a search type:created and opened it as a Data Table Visualization.  
Then to add the terms aggregation the address term is not popping up.

 ![kibanabug](https://us1.discourse-cdn.com/elastic/original/3X/b/0/b0d44db5322cd7fe7bad083c4da23e194ba199e0.png)

I got 376 created, but the address is not coming up on the field to sort it.

Thanks for your help

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [September 5, 2018, 5:13pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/7 "2018-09-05T17:13:28Z")

</div>

You'll want to ensure that the `address` field is aggregatable, the easiest way to do so is to ensure it's mapping type is `keyword` and then refresh your index pattern in Kibana.

---

<div class="post-metadata">

**Author:** ![CryptArks](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CryptArks](https://discuss.elastic.co/u/CryptArks)\
**Post date:** [September 6, 2018, 9:50am UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/8 "2018-09-06T09:50:35Z")

</div>

@Brandon_Kobel  
As my data indicates, I've put address as a keyword just for this matter, but i still do not get how to make it with the aggregate.

When on discover typing type:created, I can see all the addresses on the fields on the bottom and the top 5 values of the same addresses.  
I just want to count the type:created with unique addresses.

Still can't make this work.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [September 6, 2018, 11:31am UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/9 "2018-09-06T11:31:21Z")

</div>

@CryptArks

Using the following fake data:

```auto
POST crypta/doc
{
  "address": "foo",
  "type": "created"
}

POST crypta/doc
{
  "address": "bar",
  "type": "created"
}

POST crypta/doc
{
  "address": "bar",
  "type": "created"
}

POST crypta/doc
{
  "address": "red herring",
  "type": "updated"
}

```

I'm able to create a Data Table with the following configuration:

 ![54%20AM](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0cdfed59c19a9218190dbec6408f814d272512e3.png)

Is this similar to what you're looking for?

---

<div class="post-metadata">

**Author:** ![CryptArks](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CryptArks](https://discuss.elastic.co/u/CryptArks)\
**Post date:** [September 6, 2018, 2:49pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/10 "2018-09-06T14:49:37Z")

</div>

@Brandon_Kobel  
Thank you Brandon! this helped me quite a lot,  
Doing this I do have that same view as yours : But I have around 500 Created now, and when i apply the aggregation only 6-7 are showing up in my table.

Changing the size does not change it and adding 100 per page in Option adds me more line but not values

How do I change the N value displayed on my table?

Thanks again!

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [September 6, 2018, 5:57pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/11 "2018-09-06T17:57:34Z")

</div>

You'll want to change the "Size" of the terms aggregation:

 ![51%20PM](https://us1.discourse-cdn.com/elastic/original/3X/5/6/5664cb20592e7ada86837f29e0f8e0aecff82893.png)

---

<div class="post-metadata">

**Author:** ![CryptArks](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CryptArks](https://discuss.elastic.co/u/CryptArks)\
**Post date:** [September 11, 2018, 1:01pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/12 "2018-09-11T13:01:40Z")

</div>

Hi @Brandon_Kobel,  
Thanks for your answer so far.  
Is there no way to put this as a query so that I can visualize this as a line/area/vertical bar?

Thanks

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [September 11, 2018, 1:22pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/13 "2018-09-11T13:22:12Z")

</div>

Hey @CryptArks, you can build a Line/Area/Vertical-bar chart using the same aggregations to get a visual output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2018, 1:22pm UTC](https://discuss.elastic.co/t/help-on-a-special-visualisation/147075/14 "2018-10-09T13:22:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
