# Lens Table - "wrong" selection of top N elements

**URL:** <https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784>\
**Category:** Kibana\
**Created:** [December 21, 2022, 3:54pm UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784 "2022-12-21T15:54:32Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![tinrik](https://avatars.discourse-cdn.com/v4/letter/t/d78d45/32.png) [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Post date:** [December 21, 2022, 3:54pm UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784/1 "2022-12-21T15:54:32Z")

</div>

Hi!

I want to display a table like this:

```auto
| File Name | Number of warnings |
| path/to/foo.cpp | 123 |
| path/to/bar.cpp | 30 |
| path/to/baz.cpp | 15 |

```

They should be ordered by descending number of warnings.

So far so good with a Lens Table. However I noticed a problem. I have around 10.000 different files, whereas the Table can display at most 1000 rows. The problem is that Kibana will first pick the first 1000 files alphabetically, and then apply the sorting based on warnings. This means that there could be other 9000 files with even more warnings than the first one displayed.

Is there a good way to pick the top 1000 files based on number of warnings, instead of alphabetically?

Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 21, 2022, 5:09pm UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784/2 "2022-12-21T17:09:06Z")

</div>

Hi @tinrik

> [@tinrik](#):
>
> The problem is that Kibana will first pick the first 1000 files alphabetically, and then apply the sorting based on warnings. This means that there could be other 9000 files with even more warnings than the first one displayed.

What Version Of Kibana / Stack?

Please Show Exactly All the Settings you are using to build the Table

Here is my in 8.5.3 Example Doing a Sum there far more values than 5 but Ranks the Top 5 by the calculation

 ![Screen Shot 2022-12-21 at 9.12.38 AM](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c9458188ce2ee312d3283f45e279c2def97bcf8e.jpeg)

---

<div class="post-metadata">

**Author:** ![tinrik](https://avatars.discourse-cdn.com/v4/letter/t/d78d45/32.png) [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Post date:** [December 22, 2022, 7:58am UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784/3 "2022-12-22T07:58:59Z")

</div>

Thanks for the quick reply @stephenb !

I am running Kibana 7.16.1. This is what my settings look like:

 ![Screenshot from 2022-12-22 08-53-04](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d37e3bae133ade93fb8debaadf537d04f331bed4.png)

I realized that I'm also not using a "Quick Function", like "sum", but rather I have my own formula:

![Screenshot from 2022-12-22 08-57-30](https://us1.discourse-cdn.com/elastic/original/3X/5/4/542944f038e4011fe3e7ba1540005ead075539c1.png)

In this case a given file might be guarded (owned) by multiple people, so I need to divide by the number of guardians to get the real number of violations in a given file (otherwise it's double-counted).

If I switch over to using the Quick Function "sum", then I can choose "Rank by: Violations" and works as expected. Is there anything I need to do to enable Rank by using a custom formula?

Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 22, 2022, 3:37pm UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784/4 "2022-12-22T15:37:08Z")

</div>

I believe Sorting by Custom Formula is on the Road Map not sure when that is coming

Did you simply try to sort by the header...

 ![Screen Shot 2022-12-22 at 7.35.23 AM](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f5c0d0be27540655694868c50ed4ff5177a140cc.png)

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [December 22, 2022, 3:48pm UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784/5 "2022-12-22T15:48:34Z")

</div>

In recent versions of Lens there will be possible to specify a custom metric for Top values ranking, similar to the previous Visualization feature: [[Lens] Custom rank agg for top values / pick hidden metrics · Issue #133991 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/133991)

As for rank by formula, there are some technical challenges to overcome first, but you can follow the progress on this issue: [[Lens] sort by a formula column without expanding the entire range · Issue #114951 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/114951)

---

<div class="post-metadata">

**Author:** ![tinrik](https://avatars.discourse-cdn.com/v4/letter/t/d78d45/32.png) [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Post date:** [December 22, 2022, 3:58pm UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784/6 "2022-12-22T15:58:02Z")

</div>

> [@stephenb](#):
>
> Did you simply try to sort by the header...

Yes, that works, the problem is that sorting happens _after_ the first N items have been selected alphabetically.

Put it differentely, the top 10 elements of the table should not change if I choose to display 100 or 1000 elements - the top 10 are always the top 10. However I don't observe this behavior - the top 10 elements will be different depending on how many total elements I choose to display.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 22, 2022, 4:07pm UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784/7 "2022-12-22T16:07:48Z")

</div>

> [@tinrik](#):
>
> Put it differentely, the top 10 elements of the table should not change if I choose to display 100 or 1000 elements - the top 10 are always the top 10. However I don't observe this behavior - the top 10 elements will be different depending on how many total elements I choose to display.

Yes that is correct.... if your population is less than 10000 it would work if not then no.

The Rank by formula will be the correct approach when it is available

---

<div class="post-metadata">

**Author:** ![tinrik](https://avatars.discourse-cdn.com/v4/letter/t/d78d45/32.png) [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Post date:** [December 22, 2022, 4:18pm UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784/8 "2022-12-22T16:18:53Z")

</div>

Great, thanks for the clarification!

Lastly, I would like to ask if it's possible to achieve what I want (a Table showing the top N according to custom formula) using some other visualization element? This post is about Lens Table - can I achieve this using a "Aggregation based Table", or does it have the same limitation?

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [January 9, 2023, 11:12am UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784/9 "2023-01-09T11:12:53Z")

</div>

There's no feature like Formula in the agg based editor.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2023, 11:59am UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784/11 "2023-02-06T11:59:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
