I have bunch of logs are coming in kibana. I want to check unique users hit in timelion only.
i have alphanumeric value is coming under 'user' fields and have some segments in another fields then i want to check the trends how many user falls into those segment category ?
how can i check unique hits per user over time on timelion in segmented value ? Please suggest expression regarding timelion for unique hits.
So if I'm understanding your desire correctly, you'd like to do something like track the queries but only count them once per unique user? So the count for query cats on the 27th would be 2, not 3, because bob's query would only be counted once.
I think you should be able to use something like this .es(interval=2h, index=search*, timefield=timestamp, split=query.keyword:3, metric=cardinality:user.keyword)
The chart on the left is missing the cardinality metric, while the chart on the right has it added. You can see that on the 27th, the cats query count is only 2.