# Count over Time

**URL:** <https://discuss.elastic.co/t/count-over-time/293653>\
**Category:** Kibana\
**Created:** [January 6, 2022, 2:28pm UTC](https://discuss.elastic.co/t/count-over-time/293653 "2022-01-06T14:28:43Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![BoKu](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Post date:** [January 6, 2022, 2:28pm UTC](https://discuss.elastic.co/t/count-over-time/293653/1 "2022-01-06T14:28:43Z")

</div>

Hello and a happy new year,

i ingest the Transports Logs from several Exchange Server via Logstash into Elastic.  
I'd like to count the TOP 10 Sender Adresses and TOP 10 Recipient Adresses in a given Timerange, like the one i set on a dashboard.  
Like this:  
 ![top_senders_msg_breakdown_tjlppt](https://us1.discourse-cdn.com/elastic/original/3X/8/8/8882e57bcee47fa3092c73e59068ce0e41f8d976.jpeg)

For example: i want to know which 10 Senders send the most Mails (and how much) in the last 12 hours (or 24 hour or so on).

Additionally: i'd like to do the same with the overall count of send and recieved mails, but not in total but in the give / set timerange of the dashboard.  
(Source: [Analysing Exchange (2013) Message Tracking Logs using NXLog & ELK (ElasticSearch, Logstash, Kibana) | Elijah Paul](https://elijahpaul.co.uk/analysing-exchange-2013-message-tracking-logs-using-elk-elasticsearch-logstash-kibana/))

Elastic, Kibana and logstash are all updates to the current version 7.16.2.

Any ideas?

Kind regards  
Boris

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [January 6, 2022, 3:49pm UTC](https://discuss.elastic.co/t/count-over-time/293653/2 "2022-01-06T15:49:41Z")

</div>

Hi Boris,

Happy New Year to you, too. I think you want to create a separate visualization each for the Top 10 Senders and Top 10 Recipients. You can create these visualizations in Lens by dragging the appropriate field (example: `sender_addresss`) into the chart. By default it will aggregate the count by the `sender_address`. Then create another visualization with the `recipient_address` field. Add both visualizations to a Dashboard and change the Time Picker to the duration you want. The visualizations should update automatically.

The overall count of emails can also be created in Lens, but you may want to change the visualization type to "Metric" rather than "Bar Vertical Stacked".

Let me know if you have any other questions.

---

<div class="post-metadata">

**Author:** ![BoKu](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Post date:** [January 7, 2022, 6:14am UTC](https://discuss.elastic.co/t/count-over-time/293653/3 "2022-01-07T06:14:04Z")

</div>

Hi Nick,

thanks for your answer. I exactly did that, BUT that doesn't work. To be more specific, when i change the timerange with the Time Picker, lets say from Today to 15m the visualizations are not updated, no matter what time range i set the visualization counts ALL Sender\_adresses / Recipient\_adresses since start of the ingest, as you can see in the screenshots.

 ![Count Sender and Recipients Today](https://us1.discourse-cdn.com/elastic/original/3X/6/7/6740f6a7dd2ae58290f0b36507f29b1b9d29589f.png)  
 ![Count Sender and Recipients 15m](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a1b965b9fb33dff2aba18f44465274872c8e8380.png)  
(Please ignore the fact, that there are just TOP 5 Recipients, there is another Problem displaying 10 recipients)

Greets Boris

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 7, 2022, 8:03am UTC](https://discuss.elastic.co/t/count-over-time/293653/4 "2022-01-07T08:03:41Z")

</div>

Hi,  
Have you set an appropriate timestamp field when creating the index pattern?  
The "Time Picker" works as range query for the timestamp field of the index pattern, which you can check via Edit Visualization \> Inspect \> Request.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8d269a6fa9b95c1cc7dc94b64b65fbfaebc94314.png)

If you want to control the time range of aggregation by "Time Picker", you need to specify that datetime field for the timestamp field of the index pattern.

---

<div class="post-metadata">

**Author:** ![BoKu](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Post date:** [January 7, 2022, 9:55am UTC](https://discuss.elastic.co/t/count-over-time/293653/5 "2022-01-07T09:55:17Z")

</div>

Hi,

i think, that the pattern is setup correctly

 ![Exchange Index Tempalte Pattern](https://us1.discourse-cdn.com/elastic/original/3X/4/9/49bd45bb90e7bc58bad5b4b2578647a6dcb6bff0.png)

And this the request-view via Inspect:

 ![Count Sender](https://us1.discourse-cdn.com/elastic/original/3X/4/5/45d87d4da2d09e890f1b838e163a75eeeacf7a90.png)  
there is more then one date-time field, biut i believe that just the @timesstamp will be used.

Boris

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 7, 2022, 10:17am UTC](https://discuss.elastic.co/t/count-over-time/293653/6 "2022-01-07T10:17:28Z")

</div>

I suppose not. While it's a bit confusing, "@timestamp" field is not "timestamp field" automaticaly. If you selected "@timesstamp" field as the "Timestamp field" for the index pattern, a clock icon will show up as follows.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d412213e8906b46d0ce2b21109981f3292ff7de4.png)

Try remake index pattern and select "@timestamp" as a timestamp field.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c17fa30b5cc46d137f22d9df0e05a7b87dc46453.png)

When you check the last part of the Request of Inspect, you will find the range query and notice which field was selected as a timestamp field of the index pattern.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/954798f00b06562e79f1f92c6846bf1bcd4123d2.png)

---

<div class="post-metadata">

**Author:** ![BoKu](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Post date:** [January 7, 2022, 10:29am UTC](https://discuss.elastic.co/t/count-over-time/293653/7 "2022-01-07T10:29:20Z")

</div>

Hi,

i just recreated the index pattern and the timestamp has the clock-icon

 ![Index Pattern exchange](https://us1.discourse-cdn.com/elastic/original/3X/e/d/edd52e8004f1bc1871345b8e8912fd17ce3c0e62.png)

But the visulization still counts EVERYTHING that matches the field sender-address.

If i check the request, the "range" is completly missing, so the timerange is ignored.

```auto
{
  "aggs": {
    "0": {
      "terms": {
        "field": "sender-address.keyword",
        "order": {
          "_count": "desc"
        },
        "size": 10
      }
    }
  },
  "size": 0,
  "fields": [
    {
      "field": "@timestamp",
      "format": "date_time"
    },
    {
      "field": "date-time",
      "format": "date_time"
    },
    {
      "field": "date-time,client-ip,client-hostname,server-ip,server-hostname,source-context,connector-id,source,event-id,internal-message-id,message-id,network-message-id,recipient-address,recipient-status,total-bytes,recipient-count,related-recipient-address,reference,message-subject,sender-address,return-path,message-info,directionality,tenant-id,original-client-ip,original-server-ip,custom-data,transport-traffic-type,log-id,schema-version",
      "format": "date_time"
    }
  ],
  "script_fields": {},
  "stored_fields": [
    "*"
  ],
  "runtime_mappings": {},
  "_source": {
    "excludes": []
  },
  "query": {
    "bool": {
      "must": [],
      "filter": [],
      "should": [],
      "must_not": []
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 7, 2022, 10:47am UTC](https://discuss.elastic.co/t/count-over-time/293653/8 "2022-01-07T10:47:16Z")

</div>

That sounds strange. Sorry, I have no idea.

---

<div class="post-metadata">

**Author:** ![BoKu](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Post date:** [January 7, 2022, 11:01am UTC](https://discuss.elastic.co/t/count-over-time/293653/9 "2022-01-07T11:01:57Z")

</div>

After recreating the template now the index is completly messed up. Even in Discover the time graph is gone!  
I think there is a problem with my logstash and the data ingest. I'll have a look at this now.

Boris

---

<div class="post-metadata">

**Author:** ![BoKu](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Post date:** [January 7, 2022, 11:29am UTC](https://discuss.elastic.co/t/count-over-time/293653/10 "2022-01-07T11:29:05Z")

</div>

I just fixed the index, and now i have a working timestamp including the clock icon, but the count still doesn't work as intended.

---

<div class="post-metadata">

**Author:** ![BoKu](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Post date:** [January 7, 2022, 12:13pm UTC](https://discuss.elastic.co/t/count-over-time/293653/11 "2022-01-07T12:13:35Z")

</div>

Solved it ... it was indeed the issue with the timestamp, additionally i didn't consider the fact, that i have to recreate the index template for every space not just for the default space ... the visulizations which weren't working resides in a different space.

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [January 10, 2022, 3:56pm UTC](https://discuss.elastic.co/t/count-over-time/293653/12 "2022-01-10T15:56:23Z")

</div>

Hi Boris,

I'm glad you figured it out. Thanks for sharing your solution, too!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2022, 3:57pm UTC](https://discuss.elastic.co/t/count-over-time/293653/13 "2022-02-07T15:57:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
