# Is it possible to achieve a cardinality aggregation on a date histogram?

**URL:** <https://discuss.elastic.co/t/is-it-possible-to-achieve-a-cardinality-aggregation-on-a-date-histogram/19181>\
**Category:** Elasticsearch\
**Created:** [August 10, 2014, 7:33am UTC](https://discuss.elastic.co/t/is-it-possible-to-achieve-a-cardinality-aggregation-on-a-date-histogram/19181 "2014-08-10T07:33:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Venkateshprasanna](https://avatars.discourse-cdn.com/v4/letter/v/a4c791/32.png) [@Venkateshprasanna](https://discuss.elastic.co/u/Venkateshprasanna)\
**Post date:** [August 10, 2014, 7:33am UTC](https://discuss.elastic.co/t/is-it-possible-to-achieve-a-cardinality-aggregation-on-a-date-histogram/19181/1 "2014-08-10T07:33:21Z")

</div>

OK, this one looks a little crazy, but just wanted to check if there is  
something on these lines.

We were exploring aggregations as we worked on extracting some usage  
patterns on our IIS logs, and one of the things we felt needed was counting  
the unique days in which the same user has visited our site over a month.  
We fed the data into Elasticsearch through Logstash and started playing  
with it.

Approach 1: A date histogram aggregation helps us group accesses of people  
on different times of a day into one entry, by choosing the interval as  
"day". If we use the concept of sub-aggregations, and have a top level _terms  
aggregation_ on IP addresses, and under that, a _date histogram_ with  
interval as "day", we can get, for every IP, how many times they accessed  
out site each day.

Approach 2: Cardinality Aggregations provide us a way to count distinct IP  
addresses that have hit our site on each day, as shown in the example  
here: [http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/search-aggregations-metrics-cardinality-aggregation.html](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/search-aggregations-metrics-cardinality-aggregation.html)

But can we combine the two, and count the distinct days in which a person  
came to our site? This would require us to first aggregate on people as  
usual, then group on the days, which themselves are integrated from the  
time stamps. Is it possible to have a cardinality aggregation on top of a  
date histogram aggregation to achieve this? Are there other ways of looking  
at this - like using "month" as the interval, but only counting distinct  
days and not distinct entries? Or do you suggest dumping the data generated  
by Approach 1 to another index and perform cardinality aggregation on that  
(if there are not other dynamic approaches available)?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a9ec0e7e-dff8-41a4-9010-b8a4d3c21bd2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a9ec0e7e-dff8-41a4-9010-b8a4d3c21bd2%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:09am UTC](https://discuss.elastic.co/t/is-it-possible-to-achieve-a-cardinality-aggregation-on-a-date-histogram/19181/2 "2017-07-06T01:09:44Z")

</div>


