# How to aggregate consecutive "same" logs in Elasticsearch/Kibana?

**URL:** <https://discuss.elastic.co/t/how-to-aggregate-consecutive-same-logs-in-elasticsearch-kibana/285181>\
**Category:** Elasticsearch\
**Created:** [September 27, 2021, 12:43am UTC](https://discuss.elastic.co/t/how-to-aggregate-consecutive-same-logs-in-elasticsearch-kibana/285181 "2021-09-27T00:43:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![piglovesyou1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piglovesyou1/32/87294_2.png) [@piglovesyou1](https://discuss.elastic.co/u/piglovesyou1)\
**Post date:** [September 27, 2021, 12:43am UTC](https://discuss.elastic.co/t/how-to-aggregate-consecutive-same-logs-in-elasticsearch-kibana/285181/1 "2021-09-27T00:43:59Z")

</div>

Hi. I currently have data looking like these.

```auto
// Input
{ user: "A", status: "away", timestamp: 1 }
{ user: "A", status: "away", timestamp: 2 }
{ user: "B", status: "active", timestamp: 3 }
{ user: "A", status: "away", timestamp: 4 }
{ user: "A", status: "active", timestamp: 5 }
{ user: "A", status: "active", timestamp: 6 }
{ user: "B", status: "active", timestamp: 7 }
{ user: "B", status: "away", timestamp: 8 }
{ user: "B", status: "away", timestamp: 9 }

```

And I want to aggregate them into data like these, **picking up only the first status event.**

```auto
// Output
{ user: "A", status: "away", timestamp: 1 }
{ user: "B", status: "active", timestamp: 3 }
{ user: "A", status: "active", timestamp: 5 }
{ user: "B", status: "away", timestamp: 8 }

```

As you can see in the first data set, the same status events appear multiple times. Here I'd like to visualize them with only the first status event instead of all. Perhaps I should use Logstash, but not at this time for some reason. Do you have any good ideas?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 27, 2021, 12:59am UTC](https://discuss.elastic.co/t/how-to-aggregate-consecutive-same-logs-in-elasticsearch-kibana/285181/2 "2021-09-27T00:59:32Z")

</div>

Welcome to our community! 😃

You should be able use a top hits aggregation to get that - [Top hits aggregation | Elasticsearch Guide [7.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-top-hits-aggregation.html)

---

<div class="post-metadata">

**Author:** ![piglovesyou1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piglovesyou1/32/87294_2.png) [@piglovesyou1](https://discuss.elastic.co/u/piglovesyou1)\
**Post date:** [September 27, 2021, 2:37am UTC](https://discuss.elastic.co/t/how-to-aggregate-consecutive-same-logs-in-elasticsearch-kibana/285181/3 "2021-09-27T02:37:19Z")

</div>

Thank you so much for the response. Let me have a little more clues.

- **Would you mind writing a rough JSON example for the query?** I've read the top\_hit doc through, and it seems good but not perfect since it targets data to be aggregated by field value. In contrast, my data can continue across days, months, or years and should be aggregated by "consecutiveness".
- **Is it possible for me to express the output in Kibana visualization?** I've checked "Metrics" in Kibana can hold the top\_hit aggregation, but still not sure exactly how to.

Would you please correct me if I'm wrong? I need to learn more 🙂

---

<div class="post-metadata">

**Author:** ![piglovesyou1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piglovesyou1/32/87294_2.png) [@piglovesyou1](https://discuss.elastic.co/u/piglovesyou1)\
**Post date:** [September 28, 2021, 4:59am UTC](https://discuss.elastic.co/t/how-to-aggregate-consecutive-same-logs-in-elasticsearch-kibana/285181/4 "2021-09-28T04:59:34Z")

</div>

@warkolm So glad if you can share your additional idea 🙏

---

<div class="post-metadata">

**Author:** ![piglovesyou1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piglovesyou1/32/87294_2.png) [@piglovesyou1](https://discuss.elastic.co/u/piglovesyou1)\
**Post date:** [October 1, 2021, 2:40am UTC](https://discuss.elastic.co/t/how-to-aggregate-consecutive-same-logs-in-elasticsearch-kibana/285181/5 "2021-10-01T02:40:59Z")

</div>

bump

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2021, 2:41am UTC](https://discuss.elastic.co/t/how-to-aggregate-consecutive-same-logs-in-elasticsearch-kibana/285181/6 "2021-10-29T02:41:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
