# Auto interval creates spiky graphs, 1m interval OK

**URL:** <https://discuss.elastic.co/t/auto-interval-creates-spiky-graphs-1m-interval-ok/83349>\
**Category:** Kibana\
**Created:** [April 24, 2017, 2:54am UTC](https://discuss.elastic.co/t/auto-interval-creates-spiky-graphs-1m-interval-ok/83349 "2017-04-24T02:54:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [April 24, 2017, 2:54am UTC](https://discuss.elastic.co/t/auto-interval-creates-spiky-graphs-1m-interval-ok/83349/1 "2017-04-24T02:54:50Z")

</div>

Hi,

I'm having some problems graphing netflow bps in timelion.

Interval = auto

`$q='test_name:test_1', .es($q,metric='sum:netflow.in_bytes').scale_interval(1s).divide(1024).label('Up - KBps'), 
$q='test_name:test_1', .es($q,metric='sum:netflow.out_bytes').scale_interval(1s).divide(1024).label('Down - KBps')`

This (appears to) work but when I look at a short timeframe, lets say 15 minutes the graph is very spiky and shows too high bandwidth utilization but when I change the time frame to lets say 4 hours it looks okay.

When I change the interval to 1m it looks okay as well but the problem with that is that I can't use that because it will create too many buckets on anything over a couple of days so I want it to auto scale.

This is a screenshot from a +/- 500MB file download, downloading steady at around 1mbit. With a four hour scale the graph looks good but on a lower scale the graph is incorrect.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/f/3/f328f43778e07f2f5f1ab001e3e7d110918e113c.png)

edit: added screenshot

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [April 24, 2017, 10:48pm UTC](https://discuss.elastic.co/t/auto-interval-creates-spiky-graphs-1m-interval-ok/83349/2 "2017-04-24T22:48:14Z")

</div>

Perhaps using `.fit(scale)` or `.fit(carry)` function would smooth out the empty buckets the way you want?

---

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [April 25, 2017, 5:03am UTC](https://discuss.elastic.co/t/auto-interval-creates-spiky-graphs-1m-interval-ok/83349/3 "2017-04-25T05:03:57Z")

</div>

> [@spalger](#):
>
> Perhaps using .fit(scale) or .fit(carry) function would smooth out the empty buckets the way you want?

.fit doesn't really change anything. There is no documentation on exactly what scale or carry is supposed to do either.

The problem is that after years of people asking Kibana/timelion still does not appear to support xxx / per second properly. Scale\_interval should do that but it's not accounting for netflow records not coming in per second.

> <https://github.com/elastic/kibana/issues/4646>
>
> I have an index in which every document represents a request. I want a metric th…at would show requests per minute to measure how busy the site is.
> 
> Currently I have a count metric with query \`@timestamp: \[now-1m TO now\]\` which shows the amount of requests received during the last minute.
> 
> However, I want to use Kibana's built in duration(top-right corner). So if I select \`Last 15 minutes\`, it should get a count of documents indexed during the past 15 minutes and divide that by 15. Similarly, if I select \`Last 1 hour\`, it should divide it by 60.
> 
> Is it possible to accomplish that with the current stable version of Kibana? If not, do you think it would be a good feature to add?

E.g. if I start a large file download I can see that every minute or so a record is created with out\_bytes being 50MB and other smaller records are created as well with e.g. web browsing. The problem is that the large 50MB chunks are fed into elastic every minute and the logic timelion is applying to it is incorrect.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 23, 2017, 5:14am UTC](https://discuss.elastic.co/t/auto-interval-creates-spiky-graphs-1m-interval-ok/83349/4 "2017-05-23T05:14:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
