# Visualize unique count of IDs values by a date field

**URL:** <https://discuss.elastic.co/t/visualize-unique-count-of-ids-values-by-a-date-field/303616>\
**Category:** Kibana\
**Created:** [April 29, 2022, 3:41pm UTC](https://discuss.elastic.co/t/visualize-unique-count-of-ids-values-by-a-date-field/303616 "2022-04-29T15:41:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![H0tmilk](https://avatars.discourse-cdn.com/v4/letter/h/b782af/32.png) [@H0tmilk](https://discuss.elastic.co/u/H0tmilk)\
**Post date:** [April 29, 2022, 3:41pm UTC](https://discuss.elastic.co/t/visualize-unique-count-of-ids-values-by-a-date-field/303616/1 "2022-04-29T15:41:20Z")

</div>

Hello,

This is my data (for example) in Elasticsearch :

```auto
{
	"id": 1,
	"status": "Active",
	"title": "Incident 1",
	"@timestamp": "28/04/22"
},
{
	"id": 2,
	"status": "Active",
	"title": "Incident 2",
	"@timestamp": "28/04/22"

},
{
	"id": 3,
	"status": "Active",
	"title": "Incident 3",
	"@timestamp": "28/04/22"

},
{
	"id": 1,
	"status": "Closed",
	"title": "Incident 1",
	"@timestamp": "29/04/22"

},
{
	"id": 2,
	"status": "Closed",
	"title": "Incident 2",
	"@timestamp": "29/04/22"

}

```

As you can see, the status of the incidents with ID 1 and 2 have been changed to "Closed" and so we have 2 entries for these incidents.

I want to make a simple pie chart where I'll have the **current** status of incidents.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/9/79320ba2c3f3ced4d3169ffd6b701d83c64a4cce.png)

Unfortunately, as you can see, the pie shows 5 values (3 active, 2 closed).  
I would like to have 3 values displayed only (1 active, 2 closed).  
How can I do that ?

TL;DR  
I would like to display a unique count of incidents, considering only the incident with the most recent @timestamp field for each id.

I am using Kibana v7.17.0.

Thanks in advance !

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 30, 2022, 12:00am UTC](https://discuss.elastic.co/t/visualize-unique-count-of-ids-values-by-a-date-field/303616/2 "2022-04-30T00:00:11Z")

</div>

@H0tmilk Hi and welcome to the community!

See if you can follow me on this.. 🙂

There is a function called "Last value" that will do this for you but it requires a numeric to work with (not sure why I will ask at the bottom)

So here is my data set... Note I added a `status_code` which is an `integer` that corresponds to your `status` `keyword`

Here is the mapping and data set  
This is in 7.17.1

```auto
DELETE discuss-unique

PUT discuss-unique/
{
  "mappings": {
    "properties": {
      "id" : {"type": "keyword"},
      "status" : {"type": "keyword"},
      "status_code" : {"type": "integer"}, 
      "title" : {"type": "keyword"},
      "@timestamp" : {"type": "date" }
    }
  }
}

POST discuss-unique/_doc
{
	"id": 1,
	"status": "Active",
	"status_code": 1,
	"title": "Incident 1",
	"@timestamp": "2022-04-28"
}

POST discuss-unique/_doc
{
	"id": 2,
	"status": "Active",
	"status_code": 1,
	"title": "Incident 2",
	"@timestamp": "2022-04-28"

}

POST discuss-unique/_doc
{
	"id": 3,
	"status": "Active",
	"status_code": 1,
	"title": "Incident 3",
	"@timestamp": "2022-04-28"
}

POST discuss-unique/_doc
{
	"id": 1,
	"status": "Closed",
	"status_code": 2,
	"title": "Incident 1",
	"@timestamp": "2022-04-29"
}

POST discuss-unique/_doc
{
	"id": 2,
	"status": "Closed",
	"status_code": 2,
	"title": "Incident 2",
	"@timestamp": "2022-04-29"
}

```

Then Create a Pie Chart in Lens!

 ![Screen Shot 2022-04-29 at 4.51.14 PM](https://us1.discourse-cdn.com/elastic/original/3X/6/6/66dd9faf608f2ee15aae6b59d5c52c9b5b105d15.png)

 ![Screen Shot 2022-04-29 at 4.52.30 PM](https://us1.discourse-cdn.com/elastic/original/3X/1/3/130abc2b97e55fd76b46ac8897b4a1a391f5dcaf.png)

 ![Screen Shot 2022-04-29 at 4.53.51 PM](https://us1.discourse-cdn.com/elastic/original/3X/6/e/6edae6c18363f13688821ff422507af124475cf2.png)

Note 3 Total Incidents

**Question** : @ghudgins Why Does "Last value" only work on numerics.. when I try to use a `keyword` field it will not work... seems like last value should work on a `keyword` too ... _bug or feature?_

 ![Screen Shot 2022-04-29 at 5.12.06 PM](https://us1.discourse-cdn.com/elastic/original/3X/5/4/54d05a10a6806c2ee5b0350f9166fd5dde2ac482.png)

---

<div class="post-metadata">

**Author:** ![H0tmilk](https://avatars.discourse-cdn.com/v4/letter/h/b782af/32.png) [@H0tmilk](https://discuss.elastic.co/u/H0tmilk)\
**Post date:** [May 2, 2022, 12:41pm UTC](https://discuss.elastic.co/t/visualize-unique-count-of-ids-values-by-a-date-field/303616/3 "2022-05-02T12:41:31Z")

</div>

@stephenb thanks for you answer !

In fact it works but only for numerics fields, which doesn't seem to make sense in this case ¯\_(ツ)\_/¯

I don't know if other ways of doing it exists, in particular using aggregation based visualizations.

Thanks a lot anyway !

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 2, 2022, 2:51pm UTC](https://discuss.elastic.co/t/visualize-unique-count-of-ids-values-by-a-date-field/303616/4 "2022-05-02T14:51:31Z")

</div>

> [@H0tmilk](#):
>
> In fact it works but only for numerics fields, which doesn't seem to make sense in this case ¯\_(ツ)\_/

Yup that is why I asked ... the person I asked is a "Master" so we see what he says if / when he replies.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 30, 2022, 2:52pm UTC](https://discuss.elastic.co/t/visualize-unique-count-of-ids-values-by-a-date-field/303616/5 "2022-05-30T14:52:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
