# Conccurency in data

**URL:** <https://discuss.elastic.co/t/conccurency-in-data/184328>\
**Category:** Elasticsearch\
**Created:** [June 5, 2019, 10:26am UTC](https://discuss.elastic.co/t/conccurency-in-data/184328 "2019-06-05T10:26:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![makos63](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@makos63](https://discuss.elastic.co/u/makos63)\
**Post date:** [June 5, 2019, 10:26am UTC](https://discuss.elastic.co/t/conccurency-in-data/184328/1 "2019-06-05T10:26:59Z")

</div>

Hello,  
we want to see what was the maximum and the minimum of parallel event we had in given interval. I know that is possible in Splunk.

I tried this already, but could not rewrite Groovy script in Painless successfully

> [@Display concurrency in data on Kibana](https://discuss.elastic.co/t/display-concurrency-in-data-on-kibana/26006):
>
> I have fields with start date and duration (seconds) representing start and duration of a phone call. I would like to define concurrency (a number) when the same destination (also a field) is active within the same duration. That is if a ncall starts now for 30 seconds and another call to the same destination starts 15 seconds into the first call, concurrency should be 2 for the remaining 15 seconds. How do I define this in Kibana visualization as a line graph over time?

This is how we did it in Splunk:

> sourcetype="log" ("EXPECTED:Connected" OR "EXPECTED: Disconnected") | rex field=\_raw "SessionID":"(?\<dial\_session\>[^"]+)" | transaction host,dial\_session startswith=AVPEventConnected endswith=AVPEventDisconnected maxspan=10m | concurrency duration=duration | timechart min(concurrency) AS "Min Concurrency", max(concurrency) AS "Max Concurrency" span=200s

We really would love to replace Splunk with Elasticsearch and Kibana but we need to be sure that most of Splunk can is doable with elasticsearch.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [June 5, 2019, 11:14am UTC](https://discuss.elastic.co/t/conccurency-in-data/184328/2 "2019-06-05T11:14:17Z")

</div>

Hi makos63,

The `range` field is designed for this sort of work but currently does not support aggregations of the sort used in Kibana.  
See related discussion [here](https://discuss.elastic.co/t/how-to-aggregate-classifieds-that-have-a-date-range/179487)

---

<div class="post-metadata">

**Author:** ![makos63](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@makos63](https://discuss.elastic.co/u/makos63)\
**Post date:** [June 5, 2019, 11:42am UTC](https://discuss.elastic.co/t/conccurency-in-data/184328/3 "2019-06-05T11:42:08Z")

</div>

So there is no method to automate this process, i need to manully create data ranges in Kibana. Still i do not understand how can i retrieve all events which were active in specified data ranges.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [June 5, 2019, 12:27pm UTC](https://discuss.elastic.co/t/conccurency-in-data/184328/4 "2019-06-05T12:27:26Z")

</div>

> [@makos63](#):
>
> Still i do not understand how can i retrieve all events which were active in specified data ranges.

You could certainly use a single range search to match docs with a single range field.  
However for the purposes of aggregations and filling in bars on a Kibana histogram you'd need those docs to have a different regular date field but with an array of values. The gap between each value would have to be whatever makes sense for your visualisation e.g. weeks or days.

---

<div class="post-metadata">

**Author:** ![makos63](https://avatars.discourse-cdn.com/v4/letter/m/b19c9b/32.png) [@makos63](https://discuss.elastic.co/u/makos63)\
**Post date:** [June 13, 2019, 12:23pm UTC](https://discuss.elastic.co/t/conccurency-in-data/184328/5 "2019-06-13T12:23:15Z")

</div>

The idea worked! Thank you! It may need some more tweeking, however for now looks good enough.

Here, this is how i made it work:

> PUT test2  
> {  
> "mappings": {  
> "transaciton": {  
> "properties": {  
> "timestamp" : { "type" : "date"},  
> "sessionID": { "type": "integer" },  
> "connectAt" : {"type" : "date"},  
> "disconnectAt" : {"type" : "date"},  
> "duration": { "type": "date" },  
> "message": { "type": "text",  
> "fielddata": true},  
> "active":{"type":"boolean"}
> 
> }  
> }
> 
> PUT test2/transaciton/1  
> {  
> "timestamp":"2019-06-12T12:00:01Z",  
> "sessionID": "1",  
> "connectAt":"2019-06-12T12:00:00Z",  
> "disconnectAt":"2019-06-12T12:01:30Z",  
> "durations":[  
> {"duration":"2019-06-12T12:00:00Z"},  
> {"duration":"2019-06-12T12:00:30Z"},  
> {"duration":"2019-06-12T12:01:00Z"},  
> {"duration":"2019-06-12T12:01:30Z"}  
> ],  
> "message":"SUCCEED",  
> "active":false  
> }
> 
> PUT test2/transaciton/2  
> {  
> "timestamp":"2019-06-12T12:01:01Z",  
> "sessionID": "2",  
> "connectAt":"2019-06-12T12:01:00Z",  
> "disconnectAt":"2019-06-12T12:01:30Z",  
> "durations":[  
> {"stamp":"2019-06-12T12:01:00Z"},  
> {"stamp":"2019-06-12T12:01:30Z"}  
> ],  
> "message":"SUCCEED",  
> "active":false  
> }  
> PUT test2/transaciton/3  
> {  
> "timestamp":"2019-06-12T11:59:01Z",  
> "sessionID": "3",  
> "connectAt":"2019-06-12T11:59:00Z",  
> "disconnectAt":"2019-06-12T12:01:00Z",  
> "durations":[  
> {"stamp":"2019-06-12T11:59:00Z"},  
> {"stamp":"2019-06-12T11:59:30Z"},  
> {"stamp":"2019-06-12T12:01:00Z"}  
> ],  
> "message":"SUCCEED",  
> "active":false  
> }  
> PUT test2/transaciton/4  
> {  
> "timestamp":"2019-06-12T12:00:31Z",  
> "sessionID": "4",  
> "connectAt":"2019-06-12T12:00:30Z",  
> "disconnectAt":"2019-06-12T12:02:00Z",  
> "durations":[  
> {"stamp":"2019-06-12T12:00:00Z"},  
> {"stamp":"2019-06-12T12:00:30Z"},  
> {"stamp":"2019-06-12T12:01:00Z"},  
> {"stamp":"2019-06-12T12:01:30Z"},  
> {"stamp":"2019-06-12T12:02:00Z"}  
> ],  
> "message":"SUCCEED",  
> "active":false  
> }  
> PUT test2/transaciton/5  
> {  
> "timestamp":"2019-06-12T12:01:21Z",  
> "sessionID": "5",  
> "connectAt":"2019-06-12T12:01:20Z",  
> "disconnectAt":"2019-06-12T12:03:20Z",  
> "durations":[  
> {"stamp":"2019-06-12T12:01:20Z"},  
> {"stamp":"2019-06-12T12:01:50Z"},  
> {"stamp":"2019-06-12T12:02:20Z"},  
> {"stamp":"2019-06-12T12:02:50Z"},  
> {"stamp":"2019-06-12T12:03:20Z"}  
> ],  
> "message":"SUCCEED",  
> "active":false  
> }  
> PUT test2/transaciton/6  
> {  
> "sessionID": "6",  
> "connectAt":"2019-06-12T12:05:20Z",  
> "disconnectAt":"2019-06-12T12:07:20Z",  
> "durations":[  
> {"stamp":"2019-06-12T12:05:20Z"},  
> {"stamp":"2019-06-12T12:05:50Z"},  
> {"stamp":"2019-06-12T12:06:20Z"},  
> {"stamp":"2019-06-12T12:06:50Z"},  
> {"stamp":"2019-06-12T12:07:20Z"}  
> ],  
> "message":"SUCCEED",  
> "active":false  
> }
> 
> PUT test2/transaciton/7  
> {  
> "timestamp":"2019-06-12T12:15:21Z",  
> "sessionID": "7",  
> "connectAt":"2019-06-12T12:15:20Z",  
> "disconnectAt":"2019-06-12T12:17:20Z",  
> "durations":[  
> {"stamp":"2019-06-12T12:15:20Z"},  
> {"stamp":"2019-06-12T12:15:50Z"},  
> {"stamp":"2019-06-12T12:16:20Z"},  
> {"stamp":"2019-06-12T12:16:50Z"},  
> {"stamp":"2019-06-12T12:17:20Z"}  
> ],  
> "message":"SUCCEED",  
> "active":false  
> }

 ![26](https://us1.discourse-cdn.com/elastic/original/3X/b/0/b07a8eece93f6995cdc0556bd3ae79c013dfd24f.png)  
 ![25](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d12d7eba032a1528eee7aaa92eaac7faaa802052.png)  
 ![34](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d6c29b69996d7b52be5b2941832e9908333e8773.png)

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [June 13, 2019, 12:34pm UTC](https://discuss.elastic.co/t/conccurency-in-data/184328/6 "2019-06-13T12:34:06Z")

</div>

Glad it worked for you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2019, 12:34pm UTC](https://discuss.elastic.co/t/conccurency-in-data/184328/7 "2019-07-11T12:34:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
