# Top 5 overall filtering instead of per interval

**URL:** <https://discuss.elastic.co/t/top-5-overall-filtering-instead-of-per-interval/233835>\
**Category:** Kibana\
**Created:** [May 22, 2020, 1:44am UTC](https://discuss.elastic.co/t/top-5-overall-filtering-instead-of-per-interval/233835 "2020-05-22T01:44:28Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![BaptisteHiggs](https://avatars.discourse-cdn.com/v4/letter/b/57b2e6/32.png) [@BaptisteHiggs](https://discuss.elastic.co/u/BaptisteHiggs)\
**Post date:** [May 22, 2020, 1:44am UTC](https://discuss.elastic.co/t/top-5-overall-filtering-instead-of-per-interval/233835/1 "2020-05-22T01:44:28Z")

</div>

I have a few visualisations that are split in ways similar to these:

- The X-axis represents time
- The Y-axis is a count of usernames
- The Y-axis has a split series that uses a terms aggregation on usernames
- The Y-axis also has a split chart that uses a terms aggregation on file names

The end product of that is something that should show the activity of each user per user per file, over time. What it ends up looking like is this:

 ![tooManySplits](https://us1.discourse-cdn.com/elastic/original/3X/6/0/603db79f948417f6281a58375e622c6fd13b2d93.jpeg)

These will be filtered by project, so there aren't that many people, however, projects usually have a large amount of files, including various files that are used not that much and are less of a concern. This results in thoroughly too many files being displayed, cluttering the visualisation. The image I sent is a somewhat "okay" example of this, it gets much worse.

My question is how can I set the number of split charts that will be shown? When setting the "size" to one, I understand that this doesn't apply to the overall context but just to each of the individual intervals, and thus a lot more than one may be displayed if one is chosen (and even more than that if 2 etc. is chosen). Here's a topic I found that talked through this issue:

> [@Kibana size parameter in split bar visualizations](https://discuss.elastic.co/t/kibana-size-parameter-in-split-bar-visualizations/68361):
>
> Hello, I am having trouble understanding how Kibana 5.0 handles the size parameter in term aggregations for split bar charts. As an example, have a look [here](http://demo.elastic.co/beats/app/kibana#/visualize/edit/CPU-usage-per-process?_g=()) : The size parameter is set to 10 but the graphs shows way more fields : When set to 3, the amount of processes shown is still correct but it goes hayward from 4 on : With 3 : With 4 : Am I missing something or is that the expected behavior ? Anyway, thank you very much, in advance, for your help …

My current thoughts on how to do this is to include a DSL filter to the visualisation to try and fetch only the top 5 results of the metric I'd like to sort the charts by. However, as far as I can tell, there isn't really a way of getting the "top 5" from a filter? It's quite easy to get all the values above some value x, is there a way of calculating what x would be to capture only the top 5? I realise this is possible for aggs in the dev console, but I'm unsure of how to apply this to a DSL filter.

Thank you very much for the help, really appreciate any input!

ES: 7.6

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2020, 1:44am UTC](https://discuss.elastic.co/t/top-5-overall-filtering-instead-of-per-interval/233835/2 "2020-06-19T01:44:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
