# How can I take count by status after a split?

**URL:** <https://discuss.elastic.co/t/how-can-i-take-count-by-status-after-a-split/64878>\
**Category:** Kibana\
**Created:** [November 3, 2016, 2:07pm UTC](https://discuss.elastic.co/t/how-can-i-take-count-by-status-after-a-split/64878 "2016-11-03T14:07:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [November 3, 2016, 2:07pm UTC](https://discuss.elastic.co/t/how-can-i-take-count-by-status-after-a-split/64878/1 "2016-11-03T14:07:57Z")

</div>

Hello,

I want to create a report to show how many apps are in running status, how many apps are closed, etc  
My logs are event based. When an app has a new status it send to elk a message with the new status.

Until now I was able to do this, as kibana report looks like in image. And What I want now is to count how many apps are in status 102, 79, etc T  
There is a way to do this?

 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/80e90406020cb83b746b8f9f14709d4ac6e9d965.PNG)  
Generated query in Kibana is:

> ```
> {
> "title": "New Visualization",
> "type": "table",
> "params": {
> "perPage": 10,
> "showPartialRows": false,
> "showMeticsAtAllLevels": true
> },
> "aggs": [
> {
> "id": "1",
> "type": "max",
> "schema": "metric",
> "params": {
> "field": "date"
> }
> },
> {
> "id": "5",
> "type": "terms",
> "schema": "bucket",
> "params": {
> "field": "app_id",
> "size": 0,
> "order": "desc",
> "orderBy": "1"
> }
> },
> {
> "id": "6",
> "type": "terms",
> "schema": "bucket",
> "params": {
> "field": "new_status_id",
> "size": 1,
> "order": "desc",
> "orderBy": "_term"
> }
> }
> ],
> "listeners": {}
> }
> 
> ```

Thank you.

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [November 3, 2016, 8:06pm UTC](https://discuss.elastic.co/t/how-can-i-take-count-by-status-after-a-split/64878/2 "2016-11-03T20:06:13Z")

</div>

hi @djvidov,

you can add a 2nd metric in the "Metrics" section. Choose "Count". This will add another column to your table that gives a count for all [app\_id, new\_status\_id] tuples.

Thanks,

---

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [November 3, 2016, 10:29pm UTC](https://discuss.elastic.co/t/how-can-i-take-count-by-status-after-a-split/64878/3 "2016-11-03T22:29:06Z")

</div>

Hi Thomas,  
Thank you for your answer. I already try that and it works as you say.  
But this is not what I want. I want a count only for new\_status\_id. Because, in the end, I want to have: currently we have 75 apps in status 102 and 50 apps in status 79.  
And the reason why I added max metric by id with split rows by app\_id ordered descending orderBy 1 is because I want to take the last status from my logs.  
Thank you! 🙂

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [November 4, 2016, 2:30pm UTC](https://discuss.elastic.co/t/how-can-i-take-count-by-status-after-a-split/64878/4 "2016-11-04T14:30:52Z")

</div>

Not sure if you can do that. Any metric will apply to whatever buckets you have in that row. So if you have one row per app\_id, you won't be able to get an aggregate count in an extra column that applies to all app\_ids.

You'd be able to do this with Pipeline aggregations in ES, [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline.html), but Kibana doesn't have a UI for this yet.

You could you do a metric "Unique Count" of app\_id, for new\_status\_id terms. But then you don't limit it to the "latest" status. But if you filter on date or some other field-value to get the latest app\_id status, you could do it that way.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:34pm UTC](https://discuss.elastic.co/t/how-can-i-take-count-by-status-after-a-split/64878/5 "2017-07-06T13:34:31Z")

</div>


