# Kibana Grouping

**URL:** https://discuss.elastic.co/t/kibana-grouping/271718
**Category:** Kibana
**Created:** [April 29, 2021, 8:57pm UTC](https://discuss.elastic.co/t/kibana-grouping/271718 "2021-04-29T20:57:02Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![hsalim](https://avatars.discourse-cdn.com/v4/letter/h/c67d28/32.png) [@hsalim](https://discuss.elastic.co/u/hsalim)
#### Post date: [April 29, 2021, 8:57pm UTC](https://discuss.elastic.co/t/kibana-grouping/271718/1 "2021-04-29T20:57:02Z")

</div>

My use case calls for counting all documents in an index pattern across days. I am grouping by timestamp field by minutes that is being ingested in milliseconds. So simply trying to group milliseconds into minutes.

I get the counts for each day instead of total count for 3 days (see attached).

I have looked on this forum and elsewhere, tried some options but to no avail.

Hoping a Kibana expert can chime in and point me in the right direction.

 ![Captureqqq](https://us1.discourse-cdn.com/elastic/original/3X/a/d/ad654c1575d0364f7dc49477af2fc01e8a7c5c00.png)

---

<div class="post-metadata">

### Author: ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)
#### Post date: [April 29, 2021, 11:07pm UTC](https://discuss.elastic.co/t/kibana-grouping/271718/2 "2021-04-29T23:07:23Z")

</div>

What is the expected result?  
One number = 1200000 + 500 + 36836  
If so, just do the count, without timestamp buckets.

---

<div class="post-metadata">

### Author: ![hsalim](https://avatars.discourse-cdn.com/v4/letter/h/c67d28/32.png) [@hsalim](https://discuss.elastic.co/u/hsalim)
#### Post date: [April 30, 2021, 12:59pm UTC](https://discuss.elastic.co/t/kibana-grouping/271718/3 "2021-04-30T12:59:56Z")

</div>

I did not state my question clearly. Expected result is total for grouped docs not all docs that were ingested. For example:

Group1 (by minute) contains 5 docs by milliseconds which were ingested.  
Group2 (by minute) contains 7 docs by milliseconds which were ingested.  
Group3 (by minute) contains 3 docs by milliseconds which were ingested.

so my count should be 3 (although my index has milliseconds level data). I think this may require some scripting.

---

<div class="post-metadata">

### Author: ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)
#### Post date: [April 30, 2021, 5:59pm UTC](https://discuss.elastic.co/t/kibana-grouping/271718/4 "2021-04-30T17:59:15Z")

</div>

I'm still not sure I understand what you are trying to do. What I can recommend is that if you are being limited by the UI of the visualization, you probably need to use [Vega](https://www.elastic.co/guide/en/kibana/current/vega.html) to do more advanced visualizations. Another popular alternative is the kibana-enhanced-table plugin.

---

<div class="post-metadata">

### Author: ![hsalim](https://avatars.discourse-cdn.com/v4/letter/h/c67d28/32.png) [@hsalim](https://discuss.elastic.co/u/hsalim)
#### Post date: [April 30, 2021, 10:26pm UTC](https://discuss.elastic.co/t/kibana-grouping/271718/5 "2021-04-30T22:26:12Z")

</div>

Thanks, I will try these options.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 28, 2021, 10:26pm UTC](https://discuss.elastic.co/t/kibana-grouping/271718/6 "2021-05-28T22:26:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
