# How to use kibana to aggregate(count) based on different user scenarios

**URL:** <https://discuss.elastic.co/t/how-to-use-kibana-to-aggregate-count-based-on-different-user-scenarios/176986>\
**Category:** Kibana\
**Created:** [April 16, 2019, 2:16am UTC](https://discuss.elastic.co/t/how-to-use-kibana-to-aggregate-count-based-on-different-user-scenarios/176986 "2019-04-16T02:16:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [April 16, 2019, 2:16am UTC](https://discuss.elastic.co/t/how-to-use-kibana-to-aggregate-count-based-on-different-user-scenarios/176986/1 "2019-04-16T02:16:13Z")

</div>

Hi Team,

I have collected some user behavior data in elasticsearch end user did on Web UI. I have hundreds of events in ES and below are the event' fields .

- **userId** (which is the login user)
- **actionType** (which represents the action end user did on UI, for example, search, saved search, export search result etc..)
- **timestamp** (which means when the UI action happens)
- **module** (means which module he did the action)
- **page** ( means which page he did the on Web UI)

For example, I have below sample events,  
time stamp,userId,module,page,actionType  
14:01:01,user1,scm,ts,open  
14:01:01,user2,scm,ts,open  
14:01:02, user1,scm,search  
14:01:03, user1,scm,save  
14:01:02, user2,scm,export  
14:01:06, user1,scm,open  
14:01:06,user1,scm,export

There are two user scenarios based on above events:  
user1- open-search-save  
user1- open-export  
user2- open-export

Now the visiualization in kibana I want to see is  
**user scenario count**  
\*\*open-search-save 1 \*\*  
**open-export 2**

How kibana to achieve this??? two questions here:

1. How to write the script fields to chain the values of actionType in different events for a user
2. Can Kibana aggregate based on the script fields?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [April 17, 2019, 12:30pm UTC](https://discuss.elastic.co/t/how-to-use-kibana-to-aggregate-count-based-on-different-user-scenarios/176986/2 "2019-04-17T12:30:10Z")

</div>

A scripted field only works in the context of a single document, not on multiple documents. Also, ES isn't the best database to use for a query like this. You can show all the events of user 1, sorted by a timestamp, by using filters and the Discovery page, but that's about it.

---

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [April 17, 2019, 1:31pm UTC](https://discuss.elastic.co/t/how-to-use-kibana-to-aggregate-count-based-on-different-user-scenarios/176986/3 "2019-04-17T13:31:33Z")

</div>

Hi Marius,  
“ You can show all the events of user 1, sorted by a timestamp, by using filters and the Discovery page, but that's about it.”

can the process be visualized by kibana?

1. For showing events based on user, select userId as term to group by, right? Then the value of Y-axis is the count of aggregation. Actually I don’t want it do agg here as it’s not my expected visiualiztion chat.

2. I am thinking my requirement should not be unique,and other elk stack user might have same problem? How other user visualize such user scenario cases if scripted fields can’t achieve it? Can you please share?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2019, 1:31pm UTC](https://discuss.elastic.co/t/how-to-use-kibana-to-aggregate-count-based-on-different-user-scenarios/176986/4 "2019-05-15T13:31:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
