# Canvas - risk factor time series

**URL:** <https://discuss.elastic.co/t/canvas-risk-factor-time-series/208528>\
**Category:** Kibana\
**Created:** [November 19, 2019, 2:44pm UTC](https://discuss.elastic.co/t/canvas-risk-factor-time-series/208528 "2019-11-19T14:44:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [November 19, 2019, 2:44pm UTC](https://discuss.elastic.co/t/canvas-risk-factor-time-series/208528/1 "2019-11-19T14:44:37Z")

</div>

HI there,

Am trying to create a new timeseries canvas visualization with timelion

filters  
| timelion  
query=".es(index=nessus-\*, timefield='@timestamp', metric='count:risk\_factor.keyword', split='risk\_factor.keyword:10' ,q='!risk\_factor:None')" interval="auto" from="now-7d"  
| pointseries x="@timestamp" y="value" color="label"  
| plot defaultStyle={seriesStyle points="0" lines="5" bars="0" color="#f8dd91"}  
palette={palette "#882E72" "#B178A6" "#D6C1DE" "#1965B0" "#5289C7" "#7BAFDE" "#4EB265" "#90C987" "#CAE0AB" "#F7EE55" "#F6C141" "#F1932D" "#E8601C" "#DC050C" gradient=false}  
font={font family="'Open Sans', Helvetica, Arial, sans-serif" size=14 align="left" color="#000000" weight="normal" underline=false italic=false}  
| render css=".flot-tick-label {  
color: #fff;  
}  
"

Is there a way to put a label for these risk factors so it shows only critical, high, medium and low

and could I assign specific colour to it , like critical : red , high: orange , medium : yellow and low:blue

Please do help me figure it out

Thanks,  
Raj

 ![nessus](https://us1.discourse-cdn.com/elastic/original/3X/c/b/cbaa58662ff9b3af6f8daf1bef7f6184bfa72ff2.png)

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [November 19, 2019, 3:04pm UTC](https://discuss.elastic.co/t/canvas-risk-factor-time-series/208528/2 "2019-11-19T15:04:05Z")

</div>

Hi, you can do this, by specifying individual `es()` functions with a chained `label` call for each risk factor:

Try this timelion query:

```auto
.es(index=nessus-*, timefield='@timestamp', metric='count:risk_factor.keyword' ,q='risk_factor:Low').label('Low risk'),
.es(index=nessus-*, timefield='@timestamp', metric='count:risk_factor.keyword' ,q='risk_factor:Medium').label('Medium risk'),
.es(index=nessus-*, timefield='@timestamp', metric='count:risk_factor.keyword' ,q='risk_factor:High').label('High risk'),
.es(index=nessus-*, timefield='@timestamp', metric='count:risk_factor.keyword' ,q='risk_factor:Critical').label('Critical risk'),

```

You can specify the color by clicking the little plus icon next to "Chart style" in the display tab and adding a "Series style". There you can specify color, width and so on ( or on the expression adding `seriesStyle` parameters for each of your series

```auto
seriesStyle={seriesStyle label="Critical risk" color="red" lines="2" points="2"}

```

)

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [November 19, 2019, 4:52pm UTC](https://discuss.elastic.co/t/canvas-risk-factor-time-series/208528/3 "2019-11-19T16:52:30Z")

</div>

Thank you Joe 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2019, 4:52pm UTC](https://discuss.elastic.co/t/canvas-risk-factor-time-series/208528/4 "2019-12-17T16:52:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
