# Timelion(5.6.3) - how to query avg per bucket per distinct identifer

**URL:** <https://discuss.elastic.co/t/timelion-5-6-3-how-to-query-avg-per-bucket-per-distinct-identifer/114089>\
**Category:** Kibana\
**Created:** [January 4, 2018, 12:46pm UTC](https://discuss.elastic.co/t/timelion-5-6-3-how-to-query-avg-per-bucket-per-distinct-identifer/114089 "2018-01-04T12:46:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yoavsradware](https://avatars.discourse-cdn.com/v4/letter/y/e9c0ed/32.png) [@yoavsradware](https://discuss.elastic.co/u/yoavsradware)\
**Post date:** [January 4, 2018, 12:46pm UTC](https://discuss.elastic.co/t/timelion-5-6-3-how-to-query-avg-per-bucket-per-distinct-identifer/114089/1 "2018-01-04T12:46:58Z")

</div>

Hi all  
I have 2 devices D1 & D2 whom give every 1 minute a sample  
every sample has the change between current and last (delta).

if I have a bucket of 3 samples for D1 e.g :  
D1(10,20,30)  
I would like for a single device to show me there 20  
so this simple query :

`.es(index=ssl*, q='_type:bandwidth ',metric=avg:delta_count)`

now I need the same thing in case I have more then one device and I would like the output to represent **per device avg**  
so for  
D1(10,20,30) = 20  
D2(50,60,70) = 60  
I would like to get (60+20 )/ 2 = 40  
where this query

i need to get every device avg to calculate it

`.es(index=ssl*, q='_type:bandwidth ',metric=avg:delta_count).multiply(.es(index=ssl*, q='_type:concurrentconnections ' ,metric='cardinality:device_id.keyword'))`

is there a way to do the same thing without using cardinality:device\_id and using split instead ?

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [January 4, 2018, 5:27pm UTC](https://discuss.elastic.co/t/timelion-5-6-3-how-to-query-avg-per-bucket-per-distinct-identifer/114089/2 "2018-01-04T17:27:53Z")

</div>

cc @thomasneirynck

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2018, 5:28pm UTC](https://discuss.elastic.co/t/timelion-5-6-3-how-to-query-avg-per-bucket-per-distinct-identifer/114089/3 "2018-02-01T17:28:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
