# Complex query around heartbeats visualization

**URL:** <https://discuss.elastic.co/t/complex-query-around-heartbeats-visualization/127650>\
**Category:** Kibana\
**Created:** [April 11, 2018, 2:18pm UTC](https://discuss.elastic.co/t/complex-query-around-heartbeats-visualization/127650 "2018-04-11T14:18:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rich\_Greco](https://avatars.discourse-cdn.com/v4/letter/r/df788c/32.png) [@Rich\_Greco](https://discuss.elastic.co/u/Rich_Greco)\
**Post date:** [April 11, 2018, 2:18pm UTC](https://discuss.elastic.co/t/complex-query-around-heartbeats-visualization/127650/1 "2018-04-11T14:18:05Z")

</div>

So I have warehouses that use RF guns and the error messages are garbage. The complaint becomes its a network thing so I configured heartbeat to pingsweep these warehouses on the subnet that has the RF guns.

Problem is not all IPs pinged are actually in use and the guns are not statically assigned so I end up with many IPs showing all down.

Essentially I need a filter query to only show instances where the ip in that range have at-least 1 "up" result in the time frame requested so that the doughnut chat can work.

this image says it all I am a noob and lost, i know how to do this in splunk but not ES/Kb

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fb63cc3d7f598b08421e6a3614594b56cbbb06d7.png)

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [April 11, 2018, 6:19pm UTC](https://discuss.elastic.co/t/complex-query-around-heartbeats-visualization/127650/2 "2018-04-11T18:19:02Z")

</div>

@Rich_Greco if you add another filter that only includes documents with `monitor.status` of "up" you should get what you're looking for:

 ![02%20PM](https://us1.discourse-cdn.com/elastic/original/3X/9/0/90a031e297f632a693c192c8d9084b826f12a7b5.png)

---

<div class="post-metadata">

**Author:** ![Rich\_Greco](https://avatars.discourse-cdn.com/v4/letter/r/df788c/32.png) [@Rich\_Greco](https://discuss.elastic.co/u/Rich_Greco)\
**Post date:** [April 12, 2018, 5:23pm UTC](https://discuss.elastic.co/t/complex-query-around-heartbeats-visualization/127650/3 "2018-04-12T17:23:50Z")

</div>

So I dont just want to see what is up, I want to see the ratio of up/down for IPs where there has been atleast one up session recorded as a way of filtering out unused IPs.

If I toss in a filter it only shows up status, is there a way to filter out exclusive down status but leave in up and up/down?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [April 12, 2018, 5:53pm UTC](https://discuss.elastic.co/t/complex-query-around-heartbeats-visualization/127650/4 "2018-04-12T17:53:01Z")

</div>

@Rich_Greco I can't think of a way to do this with the built-in Visualizations without using the bucket script aggregation which isn't available yet in Kibana's visualizations.

I'd encourage you to give this [issue](([https://github.com/elastic/kibana/issues/4707](https://github.com/elastic/kibana/issues/4707)) a +1 or chime in with your specific use-case so we can prioritize it appropriately.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2018, 5:53pm UTC](https://discuss.elastic.co/t/complex-query-around-heartbeats-visualization/127650/5 "2018-05-10T17:53:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
