# Need help with simple agregation

**URL:** <https://discuss.elastic.co/t/need-help-with-simple-agregation/383274>\
**Category:** Kibana\
**Tags:** esql\
**Created:** [November 6, 2025, 3:29pm UTC](https://discuss.elastic.co/t/need-help-with-simple-agregation/383274 "2025-11-06T15:29:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![marjue](https://avatars.discourse-cdn.com/v4/letter/m/ec9cab/32.png) [@marjue](https://discuss.elastic.co/u/marjue)\
**Post date:** [November 6, 2025, 3:29pm UTC](https://discuss.elastic.co/t/need-help-with-simple-agregation/383274/1 "2025-11-06T15:29:05Z")

</div>

Hello  
I need help in a simple case but I’m too stupid.  
There is an index with simple monitoring data. The main fields are:  
`service_name (text)`  
`service_status (text)`  
`service_time (date)`

Every 5 minutes a new state for every service\_name is put to the index.

What I need is a query wich gives me the most current state of every existing service. I want to use it in a kibana dashboard.

Thanks for your help  
Marcus

---

<div class="post-metadata">

**Author:** ![DineshNaik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dineshnaik/32/89308_2.png) [@DineshNaik](https://discuss.elastic.co/u/DineshNaik)\
**Post date:** [November 6, 2025, 3:41pm UTC](https://discuss.elastic.co/t/need-help-with-simple-agregation/383274/2 "2025-11-06T15:41:04Z")

</div>

Hi @marjue  
Welcome to the community.

Try something like this:

`GET index_name/_search`  
`{`  
`"size": 0,`  
`"aggs": {`  
`"by_service": {`  
`"terms": {`  
`"field": "service_name.keyword",`  
`"size": 1000`  
`},`  
`"aggs": {`  
`"latest_state": {`  
`"top_hits": {`  
`"sort": [`  
`{`  
`"service_time": {`  
`"order": "desc"`  
`}`  
`}`  
`],`  
`"size": 1,`  
`"_source": {`  
`"includes": ["service_name", "service_status", "service_time"]`  
`}`  
`}`  
`}`  
`}`  
`}`  
`}`  
`}`

You can tweak this as per your need on size . Let me know if this helps.

---

<div class="post-metadata">

**Author:** ![marjue](https://avatars.discourse-cdn.com/v4/letter/m/ec9cab/32.png) [@marjue](https://discuss.elastic.co/u/marjue)\
**Post date:** [November 6, 2025, 4:01pm UTC](https://discuss.elastic.co/t/need-help-with-simple-agregation/383274/3 "2025-11-06T16:01:16Z")

</div>

@DineshNaik  
Thankk you  
Is it possible to use this in Kibana? I thought only ES|QL is possible.  
I’m very new to ES and Kibana.

---

<div class="post-metadata">

**Author:** ![DineshNaik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dineshnaik/32/89308_2.png) [@DineshNaik](https://discuss.elastic.co/u/DineshNaik)\
**Post date:** [November 6, 2025, 4:31pm UTC](https://discuss.elastic.co/t/need-help-with-simple-agregation/383274/4 "2025-11-06T16:31:22Z")

</div>

You can try this in kibana dev tool directly

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [November 7, 2025, 4:21am UTC](https://discuss.elastic.co/t/need-help-with-simple-agregation/383274/5 "2025-11-07T04:21:41Z")

</div>

Hello @marjue

As you want to create a dashboard to only show the recent information below are the high level steps :

1. Create a dataview say services with service\_time as the Timestamp

service\_name (text)  
service\_status (text)  
service\_time (date)

1. Create a dashboard \> Add panel \> Lens \> Select the above dataview

you can use metrics as per below screenshot

rows =\> service\_name (100)

Metrics =\>

service\_status (Last value)  
service\_time (Last value)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3e44db901c2197460f92978aa56aa019656683d.png)

And if it is ES|QL

```auto
FROM services*
| STATS latest_time = MAX(service_time) BY service_name

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f97782ccbc1ff255e4dd0de1243ba7dac10c3bc3.png)

Thanks!!
