# Visualizing time series counting first time a term appears in index

**URL:** <https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623>\
**Category:** Kibana\
**Created:** [November 28, 2018, 4:40pm UTC](https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623 "2018-11-28T16:40:45Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![DigitalMachinist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/digitalmachinist/32/40736_2.png) [@DigitalMachinist](https://discuss.elastic.co/u/DigitalMachinist)\
**Post date:** [November 28, 2018, 4:40pm UTC](https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623/1 "2018-11-28T16:40:45Z")

</div>

I'm just spending my first week or so with Kibana and trying to build dashboards to visualize performance indicators that my team is interested in tracking. At the moment, what I'd like to make a line chart time series tracking the number of first-time deposits made by users each week.

I have an index called "event-deposit-finished" that tracks completed deposit events as they occur, but for the sake of my testing right now I'm just working with historical data.

If I were querying this in SQL, I'd probably approach this in roughly the following manner:

1. Get a unique set of all users who have a completed deposit (event-deposit-finished index)
2. For each unique user, find their first finished deposit
3. Count the number of first-time deposits in each week
4. Plot the resultant series of values

My event-deposit-finished index includes a date field as well as the user ID that made the deposit.

Any ideas?

Edit:  
Moving on from here, I'm also interested in a chart that can track the time between a user registering and their first completed deposit, as we'd like to minimize this metric. I have another index "event-user-registered" that I can get the date and user ID of user registrations from. I gather this might be something I have to use timelion for, but I'm only just beginning to scratch the surface of what timelion can do.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [November 28, 2018, 5:28pm UTC](https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623/2 "2018-11-28T17:28:09Z")

</div>

Hey @DigitalMachinist, i assume the complexity that you're running into is how to determine whether or not a deposit is the very first one for a user at query-time?

---

<div class="post-metadata">

**Author:** ![DigitalMachinist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/digitalmachinist/32/40736_2.png) [@DigitalMachinist](https://discuss.elastic.co/u/DigitalMachinist)\
**Post date:** [November 28, 2018, 6:31pm UTC](https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623/3 "2018-11-28T18:31:25Z")

</div>

@Brandon_Kobel Yeah, that's basically right. I just can't seem to understand how to apply the aggregations that I'd need to do this via the visualization tools.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [November 28, 2018, 7:11pm UTC](https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623/4 "2018-11-28T19:11:35Z")

</div>

@DigitalMachinist, this is one of those situations where Elasticsearch differs from traditional SQL. Elasticsearch has really limited join based capabilities, as discussed [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/joining-queries.html) and we can use features like [pipeline aggregations](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline.html) to fill in some of the gaps as well.

The other option we have is calculating some of this on ingest. How are you currently ingesting your data into Elasticsearch, are you using the ingest node or perhaps logstash?

---

<div class="post-metadata">

**Author:** ![DigitalMachinist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/digitalmachinist/32/40736_2.png) [@DigitalMachinist](https://discuss.elastic.co/u/DigitalMachinist)\
**Post date:** [November 28, 2018, 7:17pm UTC](https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623/5 "2018-11-28T19:17:37Z")

</div>

At the moment we have a fairly naive indexing strategy. We're running a Laravel application in which we index documents into Elastic Cloud using Elasticsearch-PHP when certain events are triggered. I don't believe we have an ingest node configured, and we're not using logstash as of yet (although maybe in the future).

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [November 28, 2018, 7:32pm UTC](https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623/6 "2018-11-28T19:32:34Z")

</div>

Gotcha, if you can augment your ingest pipeline to determine whether an event is the first for a specific user it'll make creating the various visualizations inside of Kibana really easy. Otherwise, we're stuck trying to use the pipeline aggregations to try to calculate these, and there will likely be limitations to how we're able to present this data.

---

<div class="post-metadata">

**Author:** ![DigitalMachinist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/digitalmachinist/32/40736_2.png) [@DigitalMachinist](https://discuss.elastic.co/u/DigitalMachinist)\
**Post date:** [November 28, 2018, 7:43pm UTC](https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623/7 "2018-11-28T19:43:45Z")

</div>

Thanks. I'll spend a bit of time reading about the ingest process and see if I can come up with an appropriate way to handle this at that time. If I add a pipeline/processor to handle this data on ingestion, I assume I'll have to reindex the appropriate data so it can be ingested/processed properly?

Is there a particular type of processor that I should look into for this kind of task?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [November 28, 2018, 7:53pm UTC](https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623/8 "2018-11-28T19:53:55Z")

</div>

You will have to reindex your data, using Logstash and the [elasticsearch filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html) should make this not too painful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2018, 7:53pm UTC](https://discuss.elastic.co/t/visualizing-time-series-counting-first-time-a-term-appears-in-index/158623/9 "2018-12-26T19:53:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
