# Min docs count when using other aggregations

**URL:** <https://discuss.elastic.co/t/min-docs-count-when-using-other-aggregations/169487>\
**Category:** Kibana\
**Created:** [February 21, 2019, 8:52pm UTC](https://discuss.elastic.co/t/min-docs-count-when-using-other-aggregations/169487 "2019-02-21T20:52:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [February 21, 2019, 8:52pm UTC](https://discuss.elastic.co/t/min-docs-count-when-using-other-aggregations/169487/1 "2019-02-21T20:52:28Z")

</div>

Hey everyone, after a long winter I'm back to using Elastic stuff.

So, scenario: I have this data table where I get IPs and username count for those IPs. The point is to get notifications for when there are more than one username assigned to the same IP. I thought a `{"min_doc_count":2}` on advanced JSON input would solve it, but since I'm not counting docs, nothing happens.

I tried Google and browsing around the docs, but couldn't find anything with a similar scenario around. Any tip for me?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [February 22, 2019, 11:39am UTC](https://discuss.elastic.co/t/min-docs-count-when-using-other-aggregations/169487/2 "2019-02-22T11:39:10Z")

</div>

You could use an Advanced Threshold alert from Watcher for this.  
Something like:  
`WHEN count() GROUPED OVER top 10000 "ip" IS ABOVE 1 FOR THE LAST 356 days`

---

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [February 22, 2019, 4:43pm UTC](https://discuss.elastic.co/t/min-docs-count-when-using-other-aggregations/169487/3 "2019-02-22T16:43:34Z")

</div>

Ah, Watcher is off-limits for me. Gotta stick to what is open/free.

---

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [February 27, 2019, 11:59pm UTC](https://discuss.elastic.co/t/min-docs-count-when-using-other-aggregations/169487/4 "2019-02-27T23:59:55Z")

</div>

So, does that mean Kibana has no equivalent for `{"min_doc_count":2}` for aggregating other fields, instead of the doc count?

(edit) OH I've just seen another thread that I think points to my exact problem... so, it seems I just can't do this at the moment. Thanks anyway for the attention, @Marius_Dragomir!

[https://discuss.elastic.co/t/only-show-higher-values-than-x/](https://discuss.elastic.co/t/only-show-higher-values-than-x/)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2019, 12:13am UTC](https://discuss.elastic.co/t/min-docs-count-when-using-other-aggregations/169487/5 "2019-03-28T00:13:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
