# How to exclude documents from averages?

**URL:** <https://discuss.elastic.co/t/how-to-exclude-documents-from-averages/124365>\
**Category:** Kibana\
**Created:** [March 16, 2018, 8:37pm UTC](https://discuss.elastic.co/t/how-to-exclude-documents-from-averages/124365 "2018-03-16T20:37:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)\
**Post date:** [March 16, 2018, 8:37pm UTC](https://discuss.elastic.co/t/how-to-exclude-documents-from-averages/124365/1 "2018-03-16T20:37:14Z")

</div>

I have an index that contains multiple "duration" documents for lots of different events that can occur on a particular resource, identified with an "id". This id is not unique in the index since multiple event durations are logged for that particular id like this:

```auto
{ "id": 1, "event": "FOO", "duration": 2.9},
{ "id": 1, "event": "BAR", "duration": 1.4},
{ "id": 1, "event": "BAZ", "duration": 5.0},

{ "id": 2, "event": "FOO", "duration": 2.4},
{ "id": 2, "event": "BAR", "duration": 3.7},
{ "id": 2, "event": "BAZ", "duration": 4.0},

{ "id": 3, "event": "FOO", "duration": 2.3},
{ "id": 3, "event": "BAR", "duration": 3.5},
{ "id": 3, "event": "BAZ", "duration": 5.6},
...

```

I would like to average the various event durations aggregated by event, which I can do. However, I'd also like to be able to set a threshold limit on an event set if the "duration" for "FOO" events is less than some threshold value X. And then I want to include only the associated documents (by id) for which the "FOO" event's duration is \< X.

An example:  
With the above documents, I would like to average the various durations only on event sets when the `FOO` event's `duration` \< 2.5. In this example, that should result in only duration averages for documents with `id` 2 and 3 since their `FOO` event duration is less than 2.5. All documents for id 1 should be filtered out of the aggregations.

Any idea how I can set a range on `FOO` and include only the related documents for that id for which `FOO` meets the range criteria?

Thank you!

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [March 16, 2018, 9:51pm UTC](https://discuss.elastic.co/t/how-to-exclude-documents-from-averages/124365/2 "2018-03-16T21:51:30Z")

</div>

In the query bar for the visualization, you should be able to do something like "event:FOO AND duration:\<2.5".

Alternatively, you could click on "Add a filter" and create two filters, one where "event IS FOO" and another where "duration IS LESS THAN 2.5".

---

<div class="post-metadata">

**Author:** ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)\
**Post date:** [March 16, 2018, 10:22pm UTC](https://discuss.elastic.co/t/how-to-exclude-documents-from-averages/124365/3 "2018-03-16T22:22:12Z")

</div>

Thank you for your help!

This works to only include FOO documents, but I also want to include the other documents related by id. in other words, I also want the BAR and BAZ documents associated by id with the document containing FOO with a duration less than 2.5.

Does that make sense?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2018, 10:32pm UTC](https://discuss.elastic.co/t/how-to-exclude-documents-from-averages/124365/4 "2018-04-13T22:32:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
