# Unique Count Conditions

**URL:** <https://discuss.elastic.co/t/unique-count-conditions/225377>\
**Category:** Kibana\
**Created:** [March 27, 2020, 9:46am UTC](https://discuss.elastic.co/t/unique-count-conditions/225377 "2020-03-27T09:46:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Oggy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oggy/32/65184_2.png) [@Oggy](https://discuss.elastic.co/u/Oggy)\
**Post date:** [March 27, 2020, 9:46am UTC](https://discuss.elastic.co/t/unique-count-conditions/225377/1 "2020-03-27T09:46:16Z")

</div>

Hello, I need to do an unique count of items that are duplicates, let me explain.  
We use **customer.id** , it is unique for every customer. What we would like to visualize is only the customer.id's that are logged more than once in our index.

Example  
Tom - Appears once  
Jhon - Appears twice  
Simon - Appears tree times

We only want to count Jhon and Simon, so the count should be 2 instead of 3.  
Is this doable in Kibana or not ?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [March 27, 2020, 12:45pm UTC](https://discuss.elastic.co/t/unique-count-conditions/225377/2 "2020-03-27T12:45:14Z")

</div>

I can't think of a way to do this with a regular visualization, but by using transforms ([https://www.elastic.co/guide/en/elasticsearch/reference/current/transform-overview.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/transform-overview.html)) you can basically pre-aggregate your data and store the result in a separate index.  
So

```auto
{ customer.id: "Tom" }
{ customer.id: "John" }
{ customer.id: "John" }
{ customer.id: "Simon" }
{ customer.id: "Simon" }
{ customer.id: "Simon" }

```

becomes

```auto
{ customer.id: "Tom", "count": 1 }
{ customer.id: "John", "count": 2 }
{ customer.id: "Simon", "count": 3 }

```

On the second index you can now create a metric visualization, filter by `count > 1` and show the "Unique count" of `customer.id` - this will give you the value you need.

If your source index has a timefield, transforms can also be set up to continuously run in the background pre-aggregating incoming data.

---

<div class="post-metadata">

**Author:** ![Oggy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oggy/32/65184_2.png) [@Oggy](https://discuss.elastic.co/u/Oggy)\
**Post date:** [March 27, 2020, 3:40pm UTC](https://discuss.elastic.co/t/unique-count-conditions/225377/3 "2020-03-27T15:40:29Z")

</div>

Thank you, just what I needed.  
I feel I can't use time options tho?  
Changing date frame and adding data historygram does nothing.  
I have added @timestamp as an aggregate as well.

---

<div class="post-metadata">

**Author:** ![Souvik\_Das](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/souvik_das/32/107606_2.png) [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Post date:** [April 6, 2020, 6:31am UTC](https://discuss.elastic.co/t/unique-count-conditions/225377/4 "2020-04-06T06:31:49Z")

</div>

Hi Everyone. Can I use " **Transform**" from elasticsearch for Basic License?  
Actually I'm working on the basic license of Kibana and I'm unable to find that "Transform" panel in elasticsearch. I'm currently using Kibana 6.8.7

Please help!

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [April 6, 2020, 8:33am UTC](https://discuss.elastic.co/t/unique-count-conditions/225377/5 "2020-04-06T08:33:17Z")

</div>

Dataframe transforms were added in 7.3.0, so you would have to upgrade your stack. It's available in the basic license though.

---

<div class="post-metadata">

**Author:** ![Souvik\_Das](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/souvik_das/32/107606_2.png) [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Post date:** [April 6, 2020, 9:00am UTC](https://discuss.elastic.co/t/unique-count-conditions/225377/6 "2020-04-06T09:00:53Z")

</div>

Thank you so much @flash1293

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2020, 9:00am UTC](https://discuss.elastic.co/t/unique-count-conditions/225377/7 "2020-05-04T09:00:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
