# Counter rate from log entries

**URL:** <https://discuss.elastic.co/t/counter-rate-from-log-entries/328148>\
**Category:** Kibana\
**Tags:** lens\
**Created:** [March 21, 2023, 9:14am UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148 "2023-03-21T09:14:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![andreycha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreycha/32/109183_2.png) [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Post date:** [March 21, 2023, 9:14am UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148/1 "2023-03-21T09:14:23Z")

</div>

Hi,

I'm trying to cheaply get some numeric data out of our logs. There an event that we log every time it happens and I'd like to see the rate at which it happens. I've added a lens with a filter for that log message and a formula:

`counter_rate(count())`

`counter_rate()` is not designed for it, but it seems to works more or less. However on the chart I anyway see a cumulative value for every bucket, i.e. the bigger the bucket, the greater the value:

![Screenshot 2023-03-21 101234](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c6ac3681301f64b91d3e33a8d9732d50e2c4e3d9.png)

Is there still a way to get what I want by not employing full-blown metrics? I.e. to calculate the rate of log entries by a certain filter.

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [March 21, 2023, 7:41pm UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148/2 "2023-03-21T19:41:12Z")

</div>

Just to see if I understand this, you want the number of times a specific log event happens over time? With that you could just use count(), instead of counter\_rate()?

Or are you dependant on some numerical value from each event?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 22, 2023, 3:20am UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148/3 "2023-03-22T03:20:15Z")

</div>

Hi @andreycha  
As @Marius_Iversen said if you just want a rate of event it is just a count() but the under advanced you can set normalize to events/min or events / sec ...  
Which is actually the rate.

So share some data and perhaps we can help

---

<div class="post-metadata">

**Author:** ![andreycha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreycha/32/109183_2.png) [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Post date:** [March 22, 2023, 10:06am UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148/4 "2023-03-22T10:06:18Z")

</div>

> [@Marius\_Iversen](#):
>
> you want the number of times a specific log event happens over time?

Yes, exactly.

> [@stephenb](#):
>
> it is just a count() but the under advanced you can set normalize to events/min or events / sec ...

Bingo! Thanks a lot, @stephenb and @Marius_Iversen !

---

<div class="post-metadata">

**Author:** ![andreycha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreycha/32/109183_2.png) [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Post date:** [March 22, 2023, 10:17am UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148/5 "2023-03-22T10:17:37Z")

</div>

One more question though: how can I see "max" rate for every bucket? As far as I understand, normalize just calculates the rate based on the count of the events and bucket size. So there is still a problem, that I see some value for a bucket:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7af2380d1ce821db3df8df7e5ce6e551a961cdb2.png)

but when I zoom in, I see even bigger values:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/c/eca9b6947cdfcc0adc9b5d112c7ec38ceefad235.png)

I'd like to always see values as if bucket size is always 1 second.

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [March 22, 2023, 1:00pm UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148/6 "2023-03-22T13:00:49Z")

</div>

@andreycha You can either use the "max" function in Lens, or if you are using formulas, just add `max(count()))` around it.

There should not be any big normalization happening unless you apply that normalization yourself.

---

<div class="post-metadata">

**Author:** ![andreycha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreycha/32/109183_2.png) [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Post date:** [March 22, 2023, 3:31pm UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148/7 "2023-03-22T15:31:24Z")

</div>

Thank for the answer, Marius. Unfortunately, I only have these four functions available. As far as I understand, all the other functions including `max()` require a field name as argument.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c77cde1a44fce55e5b99d827ffedd30fb4f1ed7.png)

So formula editor also gives an error on `max(count())`. (I'm using Kibana 7.17 if that's important.)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/6/265be82810928ca422b888531186c2c756c5205b.png)

I rather need something like `max(rate)` where `rate` is calculated for every second rather than for current bucket size.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2023, 3:32pm UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148/8 "2023-04-19T15:32:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
