# Caculating average of the count of a query over days and plotting it in timelion

**URL:** <https://discuss.elastic.co/t/caculating-average-of-the-count-of-a-query-over-days-and-plotting-it-in-timelion/87513>\
**Category:** Elasticsearch\
**Created:** [May 30, 2017, 7:33am UTC](https://discuss.elastic.co/t/caculating-average-of-the-count-of-a-query-over-days-and-plotting-it-in-timelion/87513 "2017-05-30T07:33:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![savvy25](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@savvy25](https://discuss.elastic.co/u/savvy25)\
**Post date:** [May 30, 2017, 7:33am UTC](https://discuss.elastic.co/t/caculating-average-of-the-count-of-a-query-over-days-and-plotting-it-in-timelion/87513/1 "2017-05-30T07:33:08Z")

</div>

Hi..

I am new around ELK and I have logs of 15 days with message field, timestamp and 10-12 other fields. Now I want to generate graph in timelion with query "logged in" in message for 24 hour window showing the average of count of all 15 days at any point. I have already implemented it mannually (using timelion expression) my taking offset till 15 days adding them and dividing by 15 but everytime I receive logs for new day I would have to mannually add day 16 in the timelion [expression.Is](http://expression.Is) there any other way to do it...? (I guess probably in elasticsearch template itself)

PS: I am using elastic search 2.4.5 and kibana 4.4

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2017, 7:33am UTC](https://discuss.elastic.co/t/caculating-average-of-the-count-of-a-query-over-days-and-plotting-it-in-timelion/87513/2 "2017-06-27T07:33:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
