# Visualizations in Kibana to Display Last Updated Instance of Records

**URL:** https://discuss.elastic.co/t/visualizations-in-kibana-to-display-last-updated-instance-of-records/358072
**Category:** Kibana
**Tags:** kql-kibana-query-language, visualisation
**Created:** [April 24, 2024, 3:05am UTC](https://discuss.elastic.co/t/visualizations-in-kibana-to-display-last-updated-instance-of-records/358072 "2024-04-24T03:05:28Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![seanmb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanmb/32/133697_2.png) [@seanmb](https://discuss.elastic.co/u/seanmb)
#### Post date: [April 24, 2024, 3:05am UTC](https://discuss.elastic.co/t/visualizations-in-kibana-to-display-last-updated-instance-of-records/358072/1 "2024-04-24T03:05:28Z")

</div>

Good day,

I am relatively new to the ELK stack and still getting use to how things are done.

I am working on a solution to provide ATM statuses (whether up or down) in the form of a dashboard.

I have a csv file that looks something like this:

```auto
Time,"ATM_Id",Location,City,Branch,PingStat,Network,Status,
"2024-04-17 10:25:00",151,"ATM #1","Some City 1",N,Succeeded,CONNECTED,WORKING
"2024-04-17 10:25:00",4151,"ATM #2","Some City 2",N,Succeeded,CONNECTED,WORKING
"2024-04-17 11:00:00",13,ATM #3,"Some City 3",N,Succeeded,CONNECTED,DOWN
"2024-04-17 11:05:00",13,ATM #4,"Some City 3",N,Succeeded,CONNECTED,WORKING

```

I have successfully managed to get the data inside of elasticsearch, however, I am having a hard time figuring out how I would display the latest updated instance of the records - aggregated by atm\_id. I was able to create a queer and a corresponding table but this just dumps all the records from the csv file.

From the sample above, I would want to create a table that would display the data back to the user to depict the current status of the ATM. Note that though there are 4 records in the file, there are only 3 unique ATMs so the result should only contain 3 rows as follows:

```auto
CITY LOCATION ATM ID STATUS
Some City 1 ATM #1 151 WORKING
Some City 2 ATM #2 4151 WORKING
Some City 3 ATM #3 13 WORKING * (Since this is the most recent update in the file for this ATM)

```

I hope I hav been able to provide sufficient details and any assistance would be really appreciated as I start my ELK journey.

---

<div class="post-metadata">

### Author: ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)
#### Post date: [May 7, 2024, 4:24pm UTC](https://discuss.elastic.co/t/visualizations-in-kibana-to-display-last-updated-instance-of-records/358072/2 "2024-05-07T16:24:14Z")

</div>

Thanks for reaching out, @seanmb. Would something like what's discribed [here](https://www.youtube.com/watch?v=NRDue0dVBQI) work for you?

---

<div class="post-metadata">

### Author: ![seanmb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanmb/32/133697_2.png) [@seanmb](https://discuss.elastic.co/u/seanmb)
#### Post date: [May 8, 2024, 1:33pm UTC](https://discuss.elastic.co/t/visualizations-in-kibana-to-display-last-updated-instance-of-records/358072/3 "2024-05-08T13:33:29Z")

</div>

Thank you, this helped.

---

<div class="post-metadata">

### Author: ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)
#### Post date: [May 8, 2024, 1:35pm UTC](https://discuss.elastic.co/t/visualizations-in-kibana-to-display-last-updated-instance-of-records/358072/4 "2024-05-08T13:35:00Z")

</div>

Glad that helped, @seanmb. Let us know if you need more assistance.
