# Sum of Several "Top Hit" Values in Table or as a Metric

**URL:** <https://discuss.elastic.co/t/sum-of-several-top-hit-values-in-table-or-as-a-metric/173526>\
**Category:** Kibana\
**Created:** [March 22, 2019, 4:29pm UTC](https://discuss.elastic.co/t/sum-of-several-top-hit-values-in-table-or-as-a-metric/173526 "2019-03-22T16:29:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gehogan3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gehogan3/32/9133_2.png) [@gehogan3](https://discuss.elastic.co/u/gehogan3)\
**Post date:** [March 22, 2019, 4:29pm UTC](https://discuss.elastic.co/t/sum-of-several-top-hit-values-in-table-or-as-a-metric/173526/1 "2019-03-22T16:29:04Z")

</div>

Hello Everyone,

I have been knocking my head against the screen trying to figure this out, but the solution is being very elusive to this ES Novice.

Say my data looks something like this:  
timestamp, location, number of customers in the store

3/21/2019 09:04:14.354, Paris, 45  
3/21/2019 09:08:47.998, Madrid, 22  
3/21/2019 09:09:01.629, London, 89  
3/21/2019 10:02:51.891, Paris, 23  
3/21/2019 10:07:11.142, London, 32

This is getting updated all the time from a number of different locations.

What I am trying to do is to take the last value (Top Hit, size 1) from each store and put that in a table. (Did that...and it works great)

But I also want to Sum those top hits either at the bottom of the table, or as a single metric for use in a dashboard.

It seems to me like I should be able to do it, but for the life of me I cannot come up with the right incantation. Maybe a scripted field?

Thanks in advance...and as always: Pointers to the right place in the FM are always welcome in RTFM replies. (Where F = Frickin') 🙂

-Emmett

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [March 26, 2019, 5:42pm UTC](https://discuss.elastic.co/t/sum-of-several-top-hit-values-in-table-or-as-a-metric/173526/2 "2019-03-26T17:42:15Z")

</div>

@Bargs can you please grab this one?

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [March 26, 2019, 7:03pm UTC](https://discuss.elastic.co/t/sum-of-several-top-hit-values-in-table-or-as-a-metric/173526/3 "2019-03-26T19:03:56Z")

</div>

@gehogan3 check out this other thread where I've answered a similar question, I think it should apply to your problem as well.

> [@Sum of field of latest unique values](https://discuss.elastic.co/t/sum-of-field-of-latest-unique-values/162322):
>
> I have an X number of records like: { server: 1, size: 813, @timestamp: "2018-12-28 09:00"} { server: 2, size: 654, @timestamp: "2018-12-28 09:00"} { server: 3, size: 752, @timestamp: "2018-12-28 09:00"} { server: 1, size: 915, @timestamp: "2018-12-28 10:00"} { server: 2, size: 823, @timestamp: "2018-12-28 10:00"} { server: 3, size: 783, @timestamp: "2018-12-28 10:00"} What I would like is to show the latest total size (2521) of all the unique servers, preferably displayed with the "metric" vi…

---

<div class="post-metadata">

**Author:** ![gehogan3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gehogan3/32/9133_2.png) [@gehogan3](https://discuss.elastic.co/u/gehogan3)\
**Post date:** [April 12, 2019, 6:21pm UTC](https://discuss.elastic.co/t/sum-of-several-top-hit-values-in-table-or-as-a-metric/173526/4 "2019-04-12T18:21:10Z")

</div>

Yes!!! The vega script worked PERFECTLY!!!

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2019, 6:21pm UTC](https://discuss.elastic.co/t/sum-of-several-top-hit-values-in-table-or-as-a-metric/173526/5 "2019-05-10T18:21:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
