# Prepare the aggregation query according to the first occurence of the events

**URL:** <https://discuss.elastic.co/t/prepare-the-aggregation-query-according-to-the-first-occurence-of-the-events/359424>\
**Category:** Elasticsearch\
**Tags:** aggregations\
**Created:** [May 14, 2024, 5:03am UTC](https://discuss.elastic.co/t/prepare-the-aggregation-query-according-to-the-first-occurence-of-the-events/359424 "2024-05-14T05:03:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vish\_anand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vish_anand/32/125493_2.png) [@vish\_anand](https://discuss.elastic.co/u/vish_anand)\
**Post date:** [May 14, 2024, 5:03am UTC](https://discuss.elastic.co/t/prepare-the-aggregation-query-according-to-the-first-occurence-of-the-events/359424/1 "2024-05-14T05:03:23Z")

</div>

I have the the data of the access logs of the users in opensearch index, this data track the information of the users like at what time users access the door and got the arrival, but one user can swipe multiple time in a day so more than one entry of the user will be there.

My problem statement is : I want to find the count of the user hour wise but it should only consider the first arrival of the user, if suppose user u1 has accessed at 11 AM and then u1 again accessed at 2 PM, then I only want the count of that user at 11 AM only not at 2 PM, if I do the normal grouping aggregation by users and hour then I will get the count of that user at 11 AM and then 2 PM again which is wrong, so find the count as per the first arrival of the user and if that user is again coming then do not consider the count.

For the sake of simplicity consider I have three fields, user\_name, time\_of\_access, location, write the opensearch query as per this

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2024, 5:03am UTC](https://discuss.elastic.co/t/prepare-the-aggregation-query-according-to-the-first-occurence-of-the-events/359424/2 "2024-05-14T05:03:23Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance. See [What is OpenSearch and the OpenSearch Dashboard? | Elastic](https://www.elastic.co/elasticsearch/opensearch) for more details.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 14, 2024, 5:16am UTC](https://discuss.elastic.co/t/prepare-the-aggregation-query-according-to-the-first-occurence-of-the-events/359424/3 "2024-05-14T05:16:41Z")

</div>

Opensearch is as the bot says not supported here so I would recommend you reach out the the Opensearch community.

You may also want to have a look at [this old post](https://discuss.elastic.co/t/how-can-i-use-aggregations-to-query-distinct-values-across-all-time-grouped-by-first-seen/25482) for a discussion on what seems to be a very similar problem.
