# How to graph collapse search results?

**URL:** <https://discuss.elastic.co/t/how-to-graph-collapse-search-results/270349>\
**Category:** Kibana\
**Created:** [April 16, 2021, 8:27am UTC](https://discuss.elastic.co/t/how-to-graph-collapse-search-results/270349 "2021-04-16T08:27:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Glen\_Ogilvie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_ogilvie/32/87166_2.png) [@Glen\_Ogilvie](https://discuss.elastic.co/u/Glen_Ogilvie)\
**Post date:** [April 16, 2021, 8:27am UTC](https://discuss.elastic.co/t/how-to-graph-collapse-search-results/270349/1 "2021-04-16T08:27:27Z")

</div>

I've written a search that uses collapse:

> **[Collapse search results | Elasticsearch Guide \[7.x\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.x/collapse-search-results.html)**

To get the latest records from a time series, that I would then like to graph. I can't however find a reasonable way in Kibana to do this, with the best I've found is the top\_hits agg, which does not really work the same way as far as I can tell.

Example data might be account balances for an unknown number of accounts, collected at at unknown interval. So the data will have multiple records for the same accounts.

The collapse and sort query would be:

```auto
"sort": [{ "timestamp": { "order": "desc" } }],
"collapse": { "field": "account.keyword" }

```

This would nicely return all the different accounts that exist, and the latest details about each one, ie, balance.

Any thoughts?

I've been looking in both Kibana and Grafana, and can't find in either of these, a way to just supply a custom written query and tell it to use the returned hits as it's data source for graphing.

I also looked at using reindex to write the results of a query to a new index, but that is also not supporting collapse.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [April 19, 2021, 11:59am UTC](https://discuss.elastic.co/t/how-to-graph-collapse-search-results/270349/2 "2021-04-19T11:59:47Z")

</div>

This does indeed sound like a use case for top hits.

To a terms aggregation on `account.keyword`, then one or multiple top hits aggregations on the fields you are interested in.

A bit like this:

 ![Screenshot 2021-04-19 at 13.59.28](https://us1.discourse-cdn.com/elastic/original/3X/6/2/62ecbbbce24721316f40fe3cc6f581e0ec7a39ea.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2021, 12:00pm UTC](https://discuss.elastic.co/t/how-to-graph-collapse-search-results/270349/3 "2021-05-17T12:00:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
