# Unique Count by using visual builder metric

**URL:** <https://discuss.elastic.co/t/unique-count-by-using-visual-builder-metric/218093>\
**Category:** Kibana\
**Created:** [February 6, 2020, 6:29am UTC](https://discuss.elastic.co/t/unique-count-by-using-visual-builder-metric/218093 "2020-02-06T06:29:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sajjithreddy](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@sajjithreddy](https://discuss.elastic.co/u/sajjithreddy)\
**Post date:** [February 6, 2020, 6:29am UTC](https://discuss.elastic.co/t/unique-count-by-using-visual-builder-metric/218093/1 "2020-02-06T06:29:22Z")

</div>

I have a question that, How we can get unique count of multiple events in visual builder or any visualization kibana?  
Let me explain my question clearly.

In log stash events class name, git url and status is there. This class, git url and status is same or different when application is deployed multiple times. Here my ask is even though deployed multiple times when all these are same my count should be one, if one of these(class,url,status) are different my count should be 2. How can I group these columns and get unique count based on three fields. Any type of visualization is fine for me. Please provide me the solution.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [February 6, 2020, 9:42am UTC](https://discuss.elastic.co/t/unique-count-by-using-visual-builder-metric/218093/2 "2020-02-06T09:42:05Z")

</div>

You can do this by concatenating all relevant data in a single field of your document - either during ingest or by using [a scripted field](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html) (during ingest is preferable, as you are already using logstash you can add a pipeline step to create that field).

So if your document looks like this:

```auto
{ class: 'Abc', gitUrl: 'https://example.org', status: 'up' }

```

Then the processing should add a field like this:

```auto
{ class: 'Abc', gitUrl: 'https://example.org', status: 'up', identifier: 'Abc,https://example.org,up' }

```

Now your are able to use the regular "Unique count" aggregation on the `identifier` field available for all visualization types (bar, pie, table, metric, ...)

This logstash step could use the [mutate plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html) and look roughly like this:

```auto
mutate {
  add_field => {
    "identifier" => "%{class},%{gitUrl},%{status}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![sajjithreddy](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@sajjithreddy](https://discuss.elastic.co/u/sajjithreddy)\
**Post date:** [February 6, 2020, 6:00pm UTC](https://discuss.elastic.co/t/unique-count-by-using-visual-builder-metric/218093/3 "2020-02-06T18:00:45Z")

</div>

Hi,

Thank you for the quick response.

Unfortunately I don' have control on data and log stash. Whatever the data exist in log stash, based on that I have to do my aggregations. One more point is that in my data I don't know the value of class, git url . I know only status like deployed, build.. etc. If I write scripted field on this class, url and status, How will my query looks like? as I don't the values of class and git url.

Please help me with the solution.

Thanks..!

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [February 7, 2020, 8:33am UTC](https://discuss.elastic.co/t/unique-count-by-using-visual-builder-metric/218093/4 "2020-02-07T08:33:13Z")

</div>

Unfortunately you can't use scripted fields in visual builder, but you can use them in regular visualizations (e.g. line chart). You don't have to know the values to write the script.

Here is an example with the kibana logs sample data set (for the fields `geo.src` and `geo.dest`). Go into index pattern management and add a scripted field to your index pattern like this:

 ![Screenshot 2020-02-07 at 09.30.44](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e359690f3e617baf66807ebd1b216c41f9f45d7c.png)

Then when creating a visualization you can use the "Unique count" aggregation on that field:

 ![Screenshot 2020-02-07 at 09.29.58](https://us1.discourse-cdn.com/elastic/original/3X/4/d/4d1d6034affd6b9004ebd3831ce5cf10ddb1bfc4.png)

---

<div class="post-metadata">

**Author:** ![sajjithreddy](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@sajjithreddy](https://discuss.elastic.co/u/sajjithreddy)\
**Post date:** [February 7, 2020, 6:12pm UTC](https://discuss.elastic.co/t/unique-count-by-using-visual-builder-metric/218093/5 "2020-02-07T18:12:28Z")

</div>

Thank you so much for the help. It worked for me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2020, 6:12pm UTC](https://discuss.elastic.co/t/unique-count-by-using-visual-builder-metric/218093/6 "2020-03-06T18:12:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
