# Unique Count Aggregation filtering

**URL:** <https://discuss.elastic.co/t/unique-count-aggregation-filtering/296679>\
**Category:** Kibana\
**Created:** [February 9, 2022, 6:36am UTC](https://discuss.elastic.co/t/unique-count-aggregation-filtering/296679 "2022-02-09T06:36:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert\_Naccache](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_naccache/32/97656_2.png) [@Robert\_Naccache](https://discuss.elastic.co/u/Robert_Naccache)\
**Post date:** [February 9, 2022, 6:36am UTC](https://discuss.elastic.co/t/unique-count-aggregation-filtering/296679/1 "2022-02-09T06:36:11Z")

</div>

\*\* I was wondering if the below described is possible to display on Kibana.  
With a sample data as below, and the unique identifier being the 'sessionId'

What i'm trying to do is create any vizualization (lets say a table) where:

1. if two documents with the same sessionId has the value 'Push Notification' and 'SMS Extra Pin', this should display a count of 1 (with the label 'SMS Extra Pin')
2. if two documents with the same sessionId has on both only the value 'Push Notification', this should display a count of 1 (with the label 'Push Notification')

```auto
	"hits": [{
		"_index": "test-2022.02.07",
		"_type": "_doc",
		"_id": "1NNO034B-tVqz_6byU-H",
		"_score": 8.699561,
		"_source": {
			"methodName": "MoveNext",
			"app": "WebApi",
			"level": "INFO",
			"sessionId": "k0aneyp4uokzc0ekuz2gtd5h",
			"request": {
				"SessionKey": " ****************",
				"TransactionalPinType": "SMS Extra Pin"
			}
		}
	}, {
		"_index": "test-2022.02.07",
		"_type": "_doc",
		"_id": "1NNO034B-tVqz_6byU-H",
		"_score": 8.699561,
		"_source": {
			"methodName": "MoveNext",
			"app": "WebApi",
			"level": "INFO",
			"sessionId": "k0aneyp4uokzc0ekuz2gtd5h",
			"request": {
				"SessionKey": " ****************",
				"TransactionalPinType": "Push Notification"
			}
		}
	}]
}
```

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 9, 2022, 8:08am UTC](https://discuss.elastic.co/t/unique-count-aggregation-filtering/296679/2 "2022-02-09T08:08:42Z")

</div>

> [@Robert\_Naccache](#):
>
> 'Push Notification' and 'SMS Extra Pin', this should display a count of 1 (with the label 'SMS Extra Pin')

Is this correct? "Unique count" should be 2, isn't it?

If so, it is [cardinality aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-cardinality-aggregation.html).

---

<div class="post-metadata">

**Author:** ![Robert\_Naccache](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_naccache/32/97656_2.png) [@Robert\_Naccache](https://discuss.elastic.co/u/Robert_Naccache)\
**Post date:** [February 9, 2022, 11:32am UTC](https://discuss.elastic.co/t/unique-count-aggregation-filtering/296679/3 "2022-02-09T11:32:27Z")

</div>

So in the above Case, since the same SessionId has both "SMS Extra Pin" and "Push Notification" it should display a count of 1.

I tried using Filter with KQL while using Unique count on "sessionID"

`request.TransactionalPinType.keyword : "SMS Extra Pin" and request.TransactionalPinType.keyword : "Push Notification"`

but it returns any instance that includes "SMS Extra Pin" in a document (doesn't aggregate based on sessionID, if that makes any sense)

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 9, 2022, 12:04pm UTC](https://discuss.elastic.co/t/unique-count-aggregation-filtering/296679/4 "2022-02-09T12:04:33Z")

</div>

I don't understand why a SessionId with "2" values ("SMS Extra Pin" and "Push Notification") is counted as 1. Please define the rule of count not only showing an example.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2022, 12:05pm UTC](https://discuss.elastic.co/t/unique-count-aggregation-filtering/296679/5 "2022-03-09T12:05:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
