# Visualizing the latest Entries by a specific Field

**URL:** <https://discuss.elastic.co/t/visualizing-the-latest-entries-by-a-specific-field/276197>\
**Category:** Kibana\
**Created:** [June 16, 2021, 8:54pm UTC](https://discuss.elastic.co/t/visualizing-the-latest-entries-by-a-specific-field/276197 "2021-06-16T20:54:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![New\_ElasticFan](https://avatars.discourse-cdn.com/v4/letter/n/3be4f8/32.png) [@New\_ElasticFan](https://discuss.elastic.co/u/New_ElasticFan)\
**Post date:** [June 16, 2021, 8:54pm UTC](https://discuss.elastic.co/t/visualizing-the-latest-entries-by-a-specific-field/276197/1 "2021-06-16T20:54:44Z")

</div>

So, I am new to Elastic Stack. My index have different entries like the following.

```auto
{ "_index": "events", "_type": "_doc", "_id": "irkkDFHoBkM1o5v_kC", "_score": null, "fields": { "@timestamp": ["2021-02-18T15:46:47.000Z"], "eventData.serviceName": ["Authentication"], "eventData.serviceName.keyword": ["Authentication "], "eventData.branch": ["Y"], "eventData.branch.keyword": ["Y"], "eventData.customerNumber": ["1"], "eventData.customerNumber.keyword": ["1"] } }
{ "_index": "events", "_type": "_doc", "_id": "irLDFHoBkM1o5v_kC","_score": null, "fields": { "@timestamp": ["2021-02-18T14:44:47.000Z"], "eventData.serviceName": ["Utility Payment"], "eventData.serviceName.keyword": ["Utility Payment"], "eventData.branch": ["X"], "eventData.branch.keyword": ["X"], "eventData.customerNumber": ["1"], "eventData.customerNumber.keyword": ["1"] } } 
{ "_index": "events", "_type": "_doc", "_id": "1o5vUI8HFGxBkM_kC", "_score": null, "fields": { "@timestamp": ["2021-02-18T18:46:47.000Z"], "eventData.serviceName": ["Authentication "], "eventData.serviceName.keyword": ["Authentication "], "eventData.branch": ["Y"], "eventData.branch.keyword": ["Y"], "eventData.customerNumber": ["2"], "eventData.customerNumber.keyword": ["2"] } }
{ "_index": "events", "_type": "_doc", "_id": "1o5vUI8HFGxBkM_kC","_score": null, "fields": { "@timestamp": ["2021-02-18T19:46:47.000Z"], "eventData.serviceName": ["Authentication "], "eventData.serviceName.keyword": ["Authentication"], "eventData.branch": ["Z"], "eventData.branch.keyword": ["Z"], "eventData.customerNumber": ["2"], "eventData.customerNumber.keyword": ["2"] } }

```

Users use certain services and the branch changes.  
**I want to make a visualisation showing the numbers of users by branch using the "Authentification Service" . The issue is that I need to count only the latest entry containing "Authentification Service" per user .**  
_Top Hits_ aggregation doesn't show the desired output?  
Can anyone help ?

---

<div class="post-metadata">

**Author:** ![New\_ElasticFan](https://avatars.discourse-cdn.com/v4/letter/n/3be4f8/32.png) [@New\_ElasticFan](https://discuss.elastic.co/u/New_ElasticFan)\
**Post date:** [June 21, 2021, 10:15am UTC](https://discuss.elastic.co/t/visualizing-the-latest-entries-by-a-specific-field/276197/2 "2021-06-21T10:15:40Z")

</div>

Is there anyone who has solution to this problem? ☹

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [June 21, 2021, 2:29pm UTC](https://discuss.elastic.co/t/visualizing-the-latest-entries-by-a-specific-field/276197/3 "2021-06-21T14:29:17Z")

</div>

(In Lens) maybe try "Top values" for "Branch" and for your metric try a "Unique count" of your `customerNumber` (or other user info) so you don't get duplicates?

If you're trying to read a value out of the raw data the "Last value" can be useful....it's a bit unclear if that's your use desired vis though

Hope this helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2021, 2:29pm UTC](https://discuss.elastic.co/t/visualizing-the-latest-entries-by-a-specific-field/276197/4 "2021-07-19T14:29:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
