# How to aggregate by value and get latest results

**URL:** <https://discuss.elastic.co/t/how-to-aggregate-by-value-and-get-latest-results/206514>\
**Category:** Kibana\
**Created:** [November 5, 2019, 4:07am UTC](https://discuss.elastic.co/t/how-to-aggregate-by-value-and-get-latest-results/206514 "2019-11-05T04:07:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [November 5, 2019, 4:07am UTC](https://discuss.elastic.co/t/how-to-aggregate-by-value-and-get-latest-results/206514/1 "2019-11-05T04:07:34Z")

</div>

Hi,  
I am trying to build a table visualisation to show all clusters in storage.  
In my specific example, I am expecting to have only 2 clusters, as there are only 2 unique cluster IDs.  
I am not able to aggregate and get the latest results only.  
How should that be done?  
I tried by

> Metric Aggregation: Top Hit  
> Field: Cluster\_id  
> Aggregate with: concatenate  
> Size: 1  
> Sort on: @timestamp  
> Order: Descending

Also tried to get MAX timestamp, and all kind of try and error, with no luck.

Currently, the records are duplicated, and I don't know why.  
I would like to see the records marked in red and only those.

 ![89%20-%20Remote%20Desktop%20Connection](https://us1.discourse-cdn.com/elastic/original/3X/8/1/8118e35d95628629aad0142f8c1eb2f9ace64476.png)

Cheers!

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [November 18, 2019, 5:19pm UTC](https://discuss.elastic.co/t/how-to-aggregate-by-value-and-get-latest-results/206514/2 "2019-11-18T17:19:49Z")

</div>

What are you using for the split in the table? It should work with a Terms aggregation on the cluster ID field.

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [November 24, 2019, 9:58pm UTC](https://discuss.elastic.co/t/how-to-aggregate-by-value-and-get-latest-results/206514/3 "2019-11-24T21:58:17Z")

</div>

@Marius_Dragomir  
Not sure I understand the question.  
I split the table with the properties I want to show.

Anyhow,  
For now, my workaround/solution is to take the Max timestamp of the doc.  
Then Split the table with the fields to show and aggregate by Max(timestamp)  
Seems to work for now.

Cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2019, 9:58pm UTC](https://discuss.elastic.co/t/how-to-aggregate-by-value-and-get-latest-results/206514/4 "2019-12-22T21:58:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
