# Visualization: unique count historgram

**URL:** <https://discuss.elastic.co/t/visualization-unique-count-historgram/208281>\
**Category:** Kibana\
**Created:** [November 18, 2019, 9:58am UTC](https://discuss.elastic.co/t/visualization-unique-count-historgram/208281 "2019-11-18T09:58:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![megakoresh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/megakoresh/32/54166_2.png) [@megakoresh](https://discuss.elastic.co/u/megakoresh)\
**Post date:** [November 18, 2019, 9:58am UTC](https://discuss.elastic.co/t/visualization-unique-count-historgram/208281/1 "2019-11-18T09:58:21Z")

</div>

Hello, I have a big dataset (5+ million documents and growing), where each item is a combination of a server and update that applies to it. For example:

```
  {
    "severity": "Important",
    "erratum_id": "RHSA-2019:3878",
    "hostname": "host1.local",
    "issue_date": "2019-11-13T00:00:00Z",
    "os": "RedHat 6.10",
    "report_id": "cb75e0ec-c5c9-4826-a114-45ffe6dbc7ec",
    "hostgroup": "G1",
    "id": "5e7f4224-954c-4bcf-a411-f7bffa2a8306",
    "source": "https://satellite.local",
    "synopsis": "Important: kernel security update",
    "host_id": 1602,
    "timestamp": "2019-11-18T00:00:00+02:00"
  },
  {
    "severity": "Important",
    "erratum_id": "RHSA-2019:3878",
    "hostname": "host2.local",
    "issue_date": "2019-11-13T00:00:00Z",
    "os": "RedHat 6.10",
    "report_id": "cb75e0ec-c5c9-4826-a114-45ffe6dbc7ec",
    "hostgroup": "G1",
    "id": "d5b662f6-f085-487e-8a99-d305a602f2ee",
    "source": "https://satellite2.local",
    "synopsis": "Important: kernel security update",
    "host_id": 966,
    "timestamp": "2019-11-18T00:00:00+02:00"
  },

```

What I need is a visualization that shows number of documents within certain ranges. So similar to date histogram, except on the `unique count` of `hostname` field.

In other words I need to answer question: "How many hosts have X more than Y number of updates that apply to it". Ranges should be something like 0-10,10-100,100+  
I tried to do it via Canvas as instructed in this answer: [Kibana: Range based on count](https://discuss.elastic.co/t/kibana-range-based-on-count/199431/3) but the number of documents is too large and it crashes the browser.

Can this be done without transforming underlying data?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [November 18, 2019, 9:45pm UTC](https://discuss.elastic.co/t/visualization-unique-count-historgram/208281/2 "2019-11-18T21:45:17Z")

</div>

I don't think there's much you can do in that case. You'll have to look into rollups for the data in order to handle that .

---

<div class="post-metadata">

**Author:** ![megakoresh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/megakoresh/32/54166_2.png) [@megakoresh](https://discuss.elastic.co/u/megakoresh)\
**Post date:** [November 19, 2019, 6:56am UTC](https://discuss.elastic.co/t/visualization-unique-count-historgram/208281/3 "2019-11-19T06:56:49Z")

</div>

What do you mean by "rollups" in this context? The [experimental feature](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/rollup-overview.html) in kibana? Or something else?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [November 19, 2019, 12:21pm UTC](https://discuss.elastic.co/t/visualization-unique-count-historgram/208281/4 "2019-11-19T12:21:36Z")

</div>

That feature, yes. It's getting close to being moved from experimental to full blown. Most of the functionality is in there already.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2019, 12:30pm UTC](https://discuss.elastic.co/t/visualization-unique-count-historgram/208281/5 "2019-12-17T12:30:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
