# How to compare and sum docs with different values

**URL:** <https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364>\
**Category:** Kibana\
**Created:** [August 25, 2020, 11:18pm UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364 "2020-08-25T23:18:45Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Den1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/den1/32/73906_2.png) [@Den1](https://discuss.elastic.co/u/Den1)\
**Post date:** [August 25, 2020, 11:18pm UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364/1 "2020-08-25T23:18:45Z")

</div>

Hello,

I have docs with such data:  
sessionState: Active  
statusBoolean: true  
statusInt:-1  
timeStamp:Aug 26, 2020 @ 02:08:21.522

OR

sessionState: Disconnected  
statusBoolean: false  
statusInt:1  
timeStamp:Aug 26, 2020 @ 02:09:21.522

on time line I can see when status from Active became to Disconnected or from Disc to Act.  
But I need to SUM how many user became from Active to Disconnected during some time period.

Maybe I need to do some script field for this, that will compare privies value and if it different mark this and after that sum this marks.

Can you please help me with this?  
Thank you.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [August 26, 2020, 12:12am UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364/2 "2020-08-26T00:12:05Z")

</div>

Hello @Den

I'd recommend changing the way the data is stored. The query is simple if both events are stored in a single document -

sessionid  
activeTimestamp  
disconnectedTimestamp

---

<div class="post-metadata">

**Author:** ![Den1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/den1/32/73906_2.png) [@Den1](https://discuss.elastic.co/u/Den1)\
**Post date:** [August 26, 2020, 1:32am UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364/3 "2020-08-26T01:32:38Z")

</div>

Sorry, I probably put the question incorrectly.

 ![Wa09eJ5dxh](https://us1.discourse-cdn.com/elastic/original/3X/5/9/5993f8f14121e0800a00025ee953cc2f7684d65e.png)

Every minute I receive information from script. Information looks like  
Username:   
sessionState:   
statusBoolean:   
statusInt: \<the same if user not idle -1or true if 1 idle\>  
timeStamp:

In each doc I have string that can be Active or Disconnected.  
I need to count how many times Active changed to Disconnected.

for example on picture it was 3 times.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [August 26, 2020, 1:44am UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364/4 "2020-08-26T01:44:50Z")

</div>

> [@Den1](#):
>
> I need to count how many times Active changed to Disconnected.

I think this is the thing I'm having trouble understanding - how does this differ from counting the number of `Disconnected` values?

---

<div class="post-metadata">

**Author:** ![Den1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/den1/32/73906_2.png) [@Den1](https://discuss.elastic.co/u/Den1)\
**Post date:** [August 26, 2020, 3:39am UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364/5 "2020-08-26T03:39:56Z")

</div>

I want to know how many times the value has changed.

The counting the number of disabled records will show the total number of these records, for example, more than 100.

But there will be only a few moments when active becomes non-active.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [August 26, 2020, 4:22am UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364/6 "2020-08-26T04:22:23Z")

</div>

> The counting the number of disabled records will show the total number of these records, for example, more than 100.

So there might be multiple documents where the user's state is unchanged?

---

<div class="post-metadata">

**Author:** ![Den1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/den1/32/73906_2.png) [@Den1](https://discuss.elastic.co/u/Den1)\
**Post date:** [August 26, 2020, 4:27am UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364/7 "2020-08-26T04:27:01Z")

</div>

> [@mattkime](#):
>
> So there might be multiple documents where the user's state is unchanged?

Yes, everything is correct and it does not change for some time.  
Then it changes and when it happens I need to calculate.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [August 26, 2020, 4:33am UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364/8 "2020-08-26T04:33:01Z")

</div>

@Den1

You either need to change how you ingest the data or post process the documents.

Here's a discussion around a similar need - [Calculation time difference between two document](https://discuss.elastic.co/t/calculation-time-difference-between-two-document/174876)

---

<div class="post-metadata">

**Author:** ![Den1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/den1/32/73906_2.png) [@Den1](https://discuss.elastic.co/u/Den1)\
**Post date:** [August 26, 2020, 4:44am UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364/9 "2020-08-26T04:44:29Z")

</div>

Thank you.  
I'll take care about this in my script before post data to elastic.

The link that you gave me, I solved this problem by creating a document every minute. Which allowed me to calculate time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2020, 4:44am UTC](https://discuss.elastic.co/t/how-to-compare-and-sum-docs-with-different-values/246364/10 "2020-09-23T04:44:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
