# Kibana data normalization

**URL:** <https://discuss.elastic.co/t/kibana-data-normalization/368036>\
**Category:** Kibana\
**Tags:** lens\
**Created:** [September 30, 2024, 5:27pm UTC](https://discuss.elastic.co/t/kibana-data-normalization/368036 "2024-09-30T17:27:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![47bit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/47bit/32/137965_2.png) [@47bit](https://discuss.elastic.co/u/47bit)\
**Post date:** [September 30, 2024, 5:27pm UTC](https://discuss.elastic.co/t/kibana-data-normalization/368036/1 "2024-09-30T17:27:30Z")

</div>

I have a dataset that contains data like this:  
IP, event type, ...  
IP1, EventType1, ...  
IP2, EventType2, ...  
IP1, EventType2, ...  
IP1, EventType1, ...  
IP3, EventType2, ...

I want to show count events of every event but I want to normalize metric by count of unique IP for this event type(count(event type=EventTypen)/count(uniqueIP(event type=EventTypen)). Can I do this?

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [October 1, 2024, 9:09am UTC](https://discuss.elastic.co/t/kibana-data-normalization/368036/2 "2024-10-01T09:09:35Z")

</div>

Added #lens and removed #dashboard

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [October 1, 2024, 9:20am UTC](https://discuss.elastic.co/t/kibana-data-normalization/368036/3 "2024-10-01T09:20:58Z")

</div>

Lens supports the `unique.count` function that does exactly what you want, and can be used in a formula.

In the screenshot below, using the Kibana Flights dataset, I create a Lens table that shows for each `Carrier` the count of destinations, the unique count of destination countries, and the normalized value with those two (not looking for any meaningful value here, just to show how it works)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/2/62d904ecbf6485b974e9d9247c98d2d2ae457269.png)
