# Show unique count with buckets in Metric

**URL:** <https://discuss.elastic.co/t/show-unique-count-with-buckets-in-metric/181459>\
**Category:** Kibana\
**Created:** [May 16, 2019, 5:20pm UTC](https://discuss.elastic.co/t/show-unique-count-with-buckets-in-metric/181459 "2019-05-16T17:20:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bdsibert](https://avatars.discourse-cdn.com/v4/letter/b/258eb7/32.png) [@bdsibert](https://discuss.elastic.co/u/bdsibert)\
**Post date:** [May 16, 2019, 5:20pm UTC](https://discuss.elastic.co/t/show-unique-count-with-buckets-in-metric/181459/1 "2019-05-16T17:20:12Z")

</div>

Hi all,

Greetings! I have to admit, I am extremely new to Kibana but am trying to learn. I have developed a dashboard that shows Vulnerabilities and a corresponding remediation document. When using the data table I am able to bucket the data in a way so that the count is 1 for each item (a vulnerability on a server in an RP may appear multiple times in the index). When I export the raw data, I can see there are 7,516 items. What I am trying to do, though, is reproduce that count in a metric visualization. Although I can do a unique count in the metric, I'm struggling in creating the same row buckets that I have on my data table.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/e/ae7dcb71012db5d53c79d88770d2c14eb79dad87.png)

Is there any way to aggregate on the metric viz so that it returns a count number that is the same as what I'm getting on my data table?

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [May 16, 2019, 5:23pm UTC](https://discuss.elastic.co/t/show-unique-count-with-buckets-in-metric/181459/2 "2019-05-16T17:23:59Z")

</div>

so you want a metric-viz readout for each individual row. So in your example, that would be 752 metric visualizations?

---

<div class="post-metadata">

**Author:** ![bdsibert](https://avatars.discourse-cdn.com/v4/letter/b/258eb7/32.png) [@bdsibert](https://discuss.elastic.co/u/bdsibert)\
**Post date:** [May 16, 2019, 5:28pm UTC](https://discuss.elastic.co/t/show-unique-count-with-buckets-in-metric/181459/3 "2019-05-16T17:28:36Z")

</div>

I could be thinking about this completely wrong. Ultimately, I would like the sum of the count column that I've created on the data table. I just have no idea how to show that total number as a metric. So if I have 7,516 rows on the data table, it would display 7,516 on the metric viz (instead of the 1,168 in my attached image). Hopefully that makes sense.

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e1bd0cc1a622d9586856f79a1fd946a3f3fe2857.png)

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [May 16, 2019, 5:36pm UTC](https://discuss.elastic.co/t/show-unique-count-with-buckets-in-metric/181459/4 "2019-05-16T17:36:28Z")

</div>

I would do this with a scripted-field. [https://www.elastic.co/blog/using-painless-kibana-scripted-fields](https://www.elastic.co/blog/using-painless-kibana-scripted-fields)

Create a new field that is the concatenation of RP number- vulnerability and IP address. See [https://www.elastic.co/blog/using-painless-kibana-scripted-fields](https://www.elastic.co/blog/using-painless-kibana-scripted-fields) for an example of string-concatenation.

In the metrics visualization, then perform a unique count on that new field. It should show you how many unique combinations you have of those 3 fields.

---

<div class="post-metadata">

**Author:** ![bdsibert](https://avatars.discourse-cdn.com/v4/letter/b/258eb7/32.png) [@bdsibert](https://discuss.elastic.co/u/bdsibert)\
**Post date:** [May 16, 2019, 7:19pm UTC](https://discuss.elastic.co/t/show-unique-count-with-buckets-in-metric/181459/5 "2019-05-16T19:19:39Z")

</div>

Thank you so much for your help, Thomas--I truly appreciate it. That did the trick!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 13, 2019, 7:19pm UTC](https://discuss.elastic.co/t/show-unique-count-with-buckets-in-metric/181459/6 "2019-06-13T19:19:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
