# Timestamp for Max value

**URL:** <https://discuss.elastic.co/t/timestamp-for-max-value/263477>\
**Category:** Kibana\
**Created:** [February 5, 2021, 11:50pm UTC](https://discuss.elastic.co/t/timestamp-for-max-value/263477 "2021-02-05T23:50:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![stevezemlicka](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@stevezemlicka](https://discuss.elastic.co/u/stevezemlicka)\
**Post date:** [February 5, 2021, 11:50pm UTC](https://discuss.elastic.co/t/timestamp-for-max-value/263477/1 "2021-02-05T23:50:33Z")

</div>

I have a data table showing individual devices and two metrics for each device. Average value and Max Value. I wish to output the date/time of the max value occurrence as well. I have tried adding a max bucket metric but I can't seem to get that to work. Is that the right approach or is there another method for accomplishing this.

---

<div class="post-metadata">

**Author:** ![stevezemlicka](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@stevezemlicka](https://discuss.elastic.co/u/stevezemlicka)\
**Post date:** [February 8, 2021, 3:54pm UTC](https://discuss.elastic.co/t/timestamp-for-max-value/263477/2 "2021-02-08T15:54:15Z")

</div>

Is there a way to use the JSON option to return the datetime along with the max value result? Or is this not even possible. It seems trivial to show the date when it's already done all the work of identifying the max value.

For reference, I'm looking to show the date/time for the max occurrence as pictured below.

 ![elk-date-for-max](https://us1.discourse-cdn.com/elastic/original/3X/0/4/0489e112af39c1191407b8432c9f4e59e1bbb289.png)

Is there a way of matching a shard based on the max of one field but display another?

---

<div class="post-metadata">

**Author:** ![stevezemlicka](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@stevezemlicka](https://discuss.elastic.co/u/stevezemlicka)\
**Post date:** [February 8, 2021, 11:22pm UTC](https://discuss.elastic.co/t/timestamp-for-max-value/263477/3 "2021-02-08T23:22:57Z")

</div>

I sort of suspect this should be something related to a sibling pipeline. If I create a Max Bucket metric with a Date Histogram and field @timestamp and a submetric of the max of my intended field, I seem to return the max value again.

It seems that what I'm looking for is the ability to switch that and use the Max value of my field at the bucket level and the date histogram at the submetric level. However it doesn't seem as though the options exist to do that.

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e257da4c41e2094d9bfe9b22eb309361b9fac335.png)

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [February 9, 2021, 9:07am UTC](https://discuss.elastic.co/t/timestamp-for-max-value/263477/4 "2021-02-09T09:07:19Z")

</div>

You should be able to do this using the "Top hit" metric on the datetime field with a size of 1, ordering descending by `HrVal`(this will basically select the document with the maximum `HrVal`)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2021, 9:08am UTC](https://discuss.elastic.co/t/timestamp-for-max-value/263477/5 "2021-03-09T09:08:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
