# Can't figure out how to create time based visualisation with sub-aggregation

**URL:** <https://discuss.elastic.co/t/cant-figure-out-how-to-create-time-based-visualisation-with-sub-aggregation/285563>\
**Category:** Kibana\
**Created:** [September 30, 2021, 9:12am UTC](https://discuss.elastic.co/t/cant-figure-out-how-to-create-time-based-visualisation-with-sub-aggregation/285563 "2021-09-30T09:12:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sergey\_Ganchuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergey_ganchuk/32/95286_2.png) [@Sergey\_Ganchuk](https://discuss.elastic.co/u/Sergey_Ganchuk)\
**Post date:** [September 30, 2021, 9:12am UTC](https://discuss.elastic.co/t/cant-figure-out-how-to-create-time-based-visualisation-with-sub-aggregation/285563/1 "2021-09-30T09:12:54Z")

</div>

Hello.

I'm collecting accounting data from our cloud platform (vmname, memory, cpu, owner, etc...)  
Script is running every hour and posting document for every vm.  
I would like to visualize usage of resources by every owner in time.  
So I need first to aggregate by vmname and take average of cpu then take sum of those averages by time histogram and split it by owner.  
Is it possible to make in kibana? What kind of visualisation should it take? I'm using 7.6.1

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 1, 2021, 12:03am UTC](https://discuss.elastic.co/t/cant-figure-out-how-to-create-time-based-visualisation-with-sub-aggregation/285563/2 "2021-10-01T00:03:11Z")

</div>

Welcome to our community! 😃  
As an FYI, 7.6 is [EOL](https://www.elastic.co/support/eol) so it'd be recommended to upgrade.

> [@Sergey\_Ganchuk](#):
>
> So I need first to aggregate by vmname and take average of cpu then take sum of those averages by time histogram and split it by owner.

You will want to create an average metric on the CPU field, then do a terms aggregation by vmname and terms sub-aggregation by owner. And use a date histogram to plot over time.

If you upgrade, Lens makes this super simple;  
 ![Screen Shot 2021-10-01 at 10.02.49](https://us1.discourse-cdn.com/elastic/original/3X/6/2/6290ce38574ec3f0ad2041594e04a621834f5e04.png)

---

<div class="post-metadata">

**Author:** ![Sergey\_Ganchuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergey_ganchuk/32/95286_2.png) [@Sergey\_Ganchuk](https://discuss.elastic.co/u/Sergey_Ganchuk)\
**Post date:** [October 1, 2021, 8:32am UTC](https://discuss.elastic.co/t/cant-figure-out-how-to-create-time-based-visualisation-with-sub-aggregation/285563/3 "2021-10-01T08:32:57Z")

</div>

I would like to say, that it was super easy barely an inconvenience, but even after upgrade I can't get how to make sub-aggregation in lense.

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [October 1, 2021, 9:37am UTC](https://discuss.elastic.co/t/cant-figure-out-how-to-create-time-based-visualisation-with-sub-aggregation/285563/4 "2021-10-01T09:37:35Z")

</div>

It is not possible yet to have a multi split/break down by terms/Top values in Lens.

But in visualize, I managed to achieve this with 2 Split series + 1 X Axis Date Histogram.  
In my example I've taken the AVG of `memory`, then split by `geo.src` and a sub aggregation split (note the order) by `ip` plotted on a Date Histogram on the `X-Axis`:

 ![Screenshot 2021-10-01 at 11.35.14](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c5d9910be161aa16be292600f3c02df84be7e039.jpeg)

Is this what you are looking for?

---

<div class="post-metadata">

**Author:** ![Sergey\_Ganchuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergey_ganchuk/32/95286_2.png) [@Sergey\_Ganchuk](https://discuss.elastic.co/u/Sergey_Ganchuk)\
**Post date:** [October 1, 2021, 9:42am UTC](https://discuss.elastic.co/t/cant-figure-out-how-to-create-time-based-visualisation-with-sub-aggregation/285563/5 "2021-10-01T09:42:40Z")

</div>

not sure.  
I need to sum of all the of averages by vm.  
So first step is to get average metric (cpucount) for each vm then sum all of them aggregating by owner.  
Is it possible in kibana?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2021, 9:42am UTC](https://discuss.elastic.co/t/cant-figure-out-how-to-create-time-based-visualisation-with-sub-aggregation/285563/6 "2021-10-29T09:42:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
