# Averaging last values of multiple beats

**URL:** <https://discuss.elastic.co/t/averaging-last-values-of-multiple-beats/386182>\
**Category:** Kibana\
**Tags:** lens\
**Created:** [May 6, 2026, 2:10am UTC](https://discuss.elastic.co/t/averaging-last-values-of-multiple-beats/386182 "2026-05-06T02:10:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Benjamin\_Klein](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_klein/32/141650_2.png) [@Benjamin\_Klein](https://discuss.elastic.co/u/Benjamin_Klein)\
**Post date:** [May 6, 2026, 2:10am UTC](https://discuss.elastic.co/t/averaging-last-values-of-multiple-beats/386182/1 "2026-05-06T02:10:04Z")

</div>

I have a collection of Heartbeat monitors pinging several different hosts. Each host has multiple services being pinged (by different beats). Is there a way to display, for each host, either the number of beats that came back UP on their last ping or the average of the last summary.up value for each beat?

---

<div class="post-metadata">

**Author:** ![juancamiloll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juancamiloll/32/110326_2.png) [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Post date:** [May 6, 2026, 2:10pm UTC](https://discuss.elastic.co/t/averaging-last-values-of-multiple-beats/386182/2 "2026-05-06T14:10:34Z")

</div>

Try this

FROM heartbeat-\*  
| SORT @timestamp DESC  
| STATS latest\_status = TOP(monitor.status, 1), latest\_summary\_up = TOP(summary.up, 1) BY monitor.id, url.domain  
| EVAL is\_up = CASE(latest\_status == "up", 1, 0)  
| STATS up\_beats = SUM(is\_up), avg\_up\_summary = AVG(latest\_summary\_up) BY url.domain  
| LIMIT 100

---

<div class="post-metadata">

**Author:** ![Benjamin\_Klein](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_klein/32/141650_2.png) [@Benjamin\_Klein](https://discuss.elastic.co/u/Benjamin_Klein)\
**Post date:** [May 6, 2026, 6:43pm UTC](https://discuss.elastic.co/t/averaging-last-values-of-multiple-beats/386182/3 "2026-05-06T18:43:13Z")

</div>

Is it then possible to display this on a Lens visualization (such as a Heatmap)?

---

<div class="post-metadata">

**Author:** ![juancamiloll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juancamiloll/32/110326_2.png) [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Post date:** [May 6, 2026, 7:01pm UTC](https://discuss.elastic.co/t/averaging-last-values-of-multiple-beats/386182/4 "2026-05-06T19:01:43Z")

</div>

> Yes, it is absolutely possible to display this on a Lens visualization, such as a Heatmap!
> 
> Your ES|QL query is excellent for getting the aggregated `up_beats` and `avg_up_summary` per `url.domain`.
> 
> However, for a **Heatmap** specifically, which typically visualizes a matrix of two categorical fields against a metric (e.g., `host` vs. `monitor` showing its status), we'll need a slightly adjusted ES|QL query. The query you provided aggregates down to just `url.domain`, `up_beats`, and `avg_up_summary`, losing the individual `monitor.id` in the final `STATS` step.
> 
> To create a Heatmap that shows the status of _each individual monitor_ across different hosts, we'll use this ES|QL query:
> 
> ```esql
> FROM heartbeat-*
> | SORT @timestamp DESC
> | STATS latest_summary_up = TOP(summary.up, 1) BY monitor.id, url.domain
> | EVAL up_status_numeric = CASE(latest_summary_up == true, 1, 0) // 1 for UP, 0 for DOWN
> | LIMIT 1000
> 
> ```
> 
> This query will give you the `monitor.id`, `url.domain`, and a numeric `up_status_numeric` (1 for up, 0 for down) for the latest ping of each unique monitor. This format is perfect for a Heatmap.
> 
> Here are the step-by-step instructions in English to create a Heatmap in Kibana Lens using this query:
> 
> 1. **Navigate to Lens:**
> 
> 2. **Select ES|QL as Data Source:**
> 
> 3. **Paste the ES|QL Query:**
> 
> 4. **Choose Heatmap Visualization:**
> 
> 5. **Configure the Heatmap Axes:**
> 
> 6. **Adjust Color Palette (Optional):**
> 
> This will create a Heatmap where each cell represents a specific monitor on a specific host, and the color of the cell will indicate its latest 'up' or 'down' status.
> 
> * * *
> 
> **Note:** If you wanted to visualize the output of your _original_ query (which provides `url.domain`, `up_beats`, and `avg_up_summary`), a **Data Table** or **Bar Chart** would be more suitable.
> 
> - **Data Table:** Simply paste your original query into the ES|QL editor and select "Data Table" as the visualization type.
> - **Bar Chart:** For `up_beats` per `url.domain`, you could use `url.domain` on the X-axis and `up_beats` as the Y-axis metric.

---

<div class="post-metadata">

**Author:** ![Benjamin\_Klein](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_klein/32/141650_2.png) [@Benjamin\_Klein](https://discuss.elastic.co/u/Benjamin_Klein)\
**Post date:** [May 7, 2026, 6:28pm UTC](https://discuss.elastic.co/t/averaging-last-values-of-multiple-beats/386182/5 "2026-05-07T18:28:51Z")

</div>

I am not seeing “ES|QL” as a data source option in Kibana 8.19.14.
