# Kibana data table with the aggregations only on the latest records

**URL:** <https://discuss.elastic.co/t/kibana-data-table-with-the-aggregations-only-on-the-latest-records/162744>\
**Category:** Kibana\
**Created:** [January 3, 2019, 6:18am UTC](https://discuss.elastic.co/t/kibana-data-table-with-the-aggregations-only-on-the-latest-records/162744 "2019-01-03T06:18:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manjula\_Piyumal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manjula_piyumal/32/57068_2.png) [@Manjula\_Piyumal](https://discuss.elastic.co/u/Manjula_Piyumal)\
**Post date:** [January 3, 2019, 6:18am UTC](https://discuss.elastic.co/t/kibana-data-table-with-the-aggregations-only-on-the-latest-records/162744/1 "2019-01-03T06:18:01Z")

</div>

Hi All,

My application is reporting one of the database table status to elasticsearch via logstash in every hour. Example structure of a document on elasticsearch side is as below,

{  
"provider": "Provider 1",  
"subject": "Science",  
"resultsRegmonth": "2018-12",  
"countForFirstPart": 153,  
"countForSecondPart": 198,  
"countForThirdPart": 198,  
"currentLogstashIterationId": 201901020345  
"@timestamp": "2019-01-02T07:45:00.593Z"  
}

One provider can have multiple values for subjects and resultsRegmonth fielts. And the countFor\* fields have the whole summation for the given field. So I the valid records are the one with the largest value for the currentLogstashIterationId. I want to visulize this on a kibana data table like below,

Content Provider| Sum of Count for 1st section| Sum of Count for 2nd section| Sum of Count for 3rd  
Provider 1 | 201 | 148 | 150  
Provider 2 | 198 | 150 | 157  
Provider 3 | 180 | 144 | 150  
Provider 4 | 170 | 143 | 147

So my problem here is, how to get the latest records for a given set of fields. Here I should get the latest value for each tuple of [provider, subject and resultsRegmonth] and get the sum of the countFor\* fields.

Sorry if it's not very clear and thanks in advance.

Manjula

---

<div class="post-metadata">

**Author:** ![Manjula\_Piyumal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manjula_piyumal/32/57068_2.png) [@Manjula\_Piyumal](https://discuss.elastic.co/u/Manjula_Piyumal)\
**Post date:** [January 7, 2019, 4:31am UTC](https://discuss.elastic.co/t/kibana-data-table-with-the-aggregations-only-on-the-latest-records/162744/2 "2019-01-07T04:31:22Z")

</div>

Hi All,

Any help on this?

Thanks

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [January 7, 2019, 12:30pm UTC](https://discuss.elastic.co/t/kibana-data-table-with-the-aggregations-only-on-the-latest-records/162744/3 "2019-01-07T12:30:41Z")

</div>

The way to get the latest value of a given field is to build something like this:

```auto
Metric Aggregation: Top Hit
Field: your_field
Aggregate with: concatenate
Size: 1
Sort on: @timestamp
Order: Descending

```

For the other data, you need to build a dashboard that show the sum. This is how I would do it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 4, 2019, 12:30pm UTC](https://discuss.elastic.co/t/kibana-data-table-with-the-aggregations-only-on-the-latest-records/162744/4 "2019-02-04T12:30:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
