# Ordering results based on derivate aggregation

**URL:** <https://discuss.elastic.co/t/ordering-results-based-on-derivate-aggregation/313954>\
**Category:** Kibana\
**Created:** [September 8, 2022, 7:17am UTC](https://discuss.elastic.co/t/ordering-results-based-on-derivate-aggregation/313954 "2022-09-08T07:17:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Toni\_Heinonen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/toni_heinonen/32/88761_2.png) [@Toni\_Heinonen](https://discuss.elastic.co/u/Toni_Heinonen)\
**Post date:** [September 8, 2022, 7:17am UTC](https://discuss.elastic.co/t/ordering-results-based-on-derivate-aggregation/313954/1 "2022-09-08T07:17:08Z")

</div>

I'm working with a audit trail data and trying to make a graph (or even a table) that would list users that have a greatest drop on usage since last month.  
So far I have tried the following.  
_TSVB_:  
I can get a percentage difference of activity level per user per month. **But** I cannot order the results based on these values.  
_Lens_:  
I can get percentage of difference of activity per month **but** I cannot split the result based on terms at all.  
_Continuous transform index_  
I created a transform index that has a monthly record per user with a record count from the audit trail. However, I cannot include derivate or serial difference aggregations on a transform.

Am I missing something or what should I try next? I cannot cope how difficult this kind of visualization is to create. Without proper ordering possibilities all of the above solutions are useless.

---

<div class="post-metadata">

**Author:** ![Marta\_Bondyra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_bondyra/32/102122_2.png) [@Marta\_Bondyra](https://discuss.elastic.co/u/Marta_Bondyra)\
**Post date:** [September 26, 2022, 1:32pm UTC](https://discuss.elastic.co/t/ordering-results-based-on-derivate-aggregation/313954/2 "2022-09-26T13:32:39Z")

</div>

Hey there, did you find your solution? Could you paste a visual that you want achieve? In Lens, you have the option to split the result by terms but I am not sure if this is what you mean:

 ![Screenshot 2022-09-26 at 15.32.31](https://us1.discourse-cdn.com/elastic/original/3X/6/a/6adae123c8dac26f04e0b0b53d21f107db80ce06.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2022, 1:33pm UTC](https://discuss.elastic.co/t/ordering-results-based-on-derivate-aggregation/313954/3 "2022-10-24T13:33:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
