# Show number of servers with a number of uniques IDs reporting

**URL:** <https://discuss.elastic.co/t/show-number-of-servers-with-a-number-of-uniques-ids-reporting/227527>\
**Category:** Kibana\
**Created:** [April 10, 2020, 3:29pm UTC](https://discuss.elastic.co/t/show-number-of-servers-with-a-number-of-uniques-ids-reporting/227527 "2020-04-10T15:29:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tisiman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tisiman/32/66127_2.png) [@tisiman](https://discuss.elastic.co/u/tisiman)\
**Post date:** [April 10, 2020, 3:29pm UTC](https://discuss.elastic.co/t/show-number-of-servers-with-a-number-of-uniques-ids-reporting/227527/1 "2020-04-10T15:29:24Z")

</div>

I have an X number of records like:

{ server: 1, ID: A1X, @timestamp: "2018-12-28 09:00"}  
{ server: 1, ID: A2X, @timestamp: "2018-12-28 09:00"}  
{ server: 1, ID: A3X, @timestamp: "2018-12-28 09:00"}  
{ server: 2, ID: B1X, @timestamp: "2018-12-28 09:00"}  
{ server: 3, ID: C1X, @timestamp: "2018-12-28 09:00"}  
{ server: 3, ID: C2X, @timestamp: "2018-12-28 09:00"}  
{ server: 4, ID: D1X, @timestamp: "2018-12-28 09:00"}  
{ server: 1, ID: A1X, @timestamp: "2018-12-28 10:00"}  
{ server: 1, ID: A3X, @timestamp: "2018-12-28 10:00"}  
{ server: 2, ID: B1X, @timestamp: "2018-12-28 10:00"}  
{ server: 3, ID: C1X, @timestamp: "2018-12-28 10:00"}  
{ server: 4, ID: D1X, @timestamp: "2018-12-28 10:00"}

Waht I would like to show in Bargraph (or Pie) is how many servers have X number of IDs reporting. IDs are not reporting every timestamp. IDs are unique Hash Valiues in Real.  
The number of servers is about 1000.

Result should be  
1 Server with 3 IDs (Server 1)  
1 Server with 2 IDs (Server 3)  
2 Servers with 1 IDs (Server 2 and 4)

So I should be able to stack Unique Count on top of Unique Count.

Any advice on how to do this? Thanks

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [April 15, 2020, 7:26am UTC](https://discuss.elastic.co/t/show-number-of-servers-with-a-number-of-uniques-ids-reporting/227527/2 "2020-04-15T07:26:54Z")

</div>

With the visualization UI it's not possible to chain aggregations like this. You can use a transform though to bring your data into the right shape to execute the query and save the pre-aggregated data: [https://www.elastic.co/guide/en/elasticsearch/reference/7.6/ecommerce-transforms.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/ecommerce-transforms.html)

By grouping by the server name and adding a cardinality metric on the ID field, the transformed dataset will look like this:

```auto
{ server: 1, ID_cardinality: 3 },
{ server: 2, ID_cardinality: 1 },
{ server: 3, ID_cardinality: 2 },
{ server: 4, ID_cardinality: 1 }

```

Now you can create a visualization based on this "view" of your data to get what you want: Splitting the pie slices by terms of `ID_cardinality` and using a "Count" aggregation for the size of the slices.

Creating this kind of transformed view can also be helpful for other insights - you can also set the transform job up to continuously add incoming data the view to keep it up to date.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2020, 7:26am UTC](https://discuss.elastic.co/t/show-number-of-servers-with-a-number-of-uniques-ids-reporting/227527/3 "2020-05-13T07:26:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
