# Create consistent graph in kibana

**URL:** <https://discuss.elastic.co/t/create-consistent-graph-in-kibana/73025>\
**Category:** Kibana\
**Created:** [January 27, 2017, 2:23pm UTC](https://discuss.elastic.co/t/create-consistent-graph-in-kibana/73025 "2017-01-27T14:23:39Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [January 27, 2017, 2:23pm UTC](https://discuss.elastic.co/t/create-consistent-graph-in-kibana/73025/1 "2017-01-27T14:23:39Z")

</div>

Hello & ty for your help !

**Context actual :**  
My stack Filebeat \> Logstash \> Elastic \> Kibana (5.1) is running

Bash script works every hour, to write data into file text named "q\_compt". Data seems like to this :

Syntax : Date ; Name script ; Name application ; data volume

**File text (q\_compt) :**  
[...]  
20170127065959;AC\_hour-C-FWK-BMA-EDR-2-Zone-C;Eroe;3218.4  
20170127065959;AC\_hour-C-FWK-BMA-EDR-2-Zone-C;UCa;15840  
20170127065959;AC\_hour-C-FWK-BMA-EDR-2-Zone-C;RM;30270  
20170127075959;AC\_hour-C-FWK-BMA-EDR-2-Zone-C;Eroe;8298.2  
20170127075959;AC\_hour-C-FWK-BMA-EDR-2-Zone-C;UCa;14385  
20170127075959;AC\_hour-C-FWK-BMA-EDR-2-Zone-C;RM;32320  
20170127085959;AC\_hour-C-FWK-BMA-EDR-2-Zone-C;Eroe;8056.4  
20170127085959;AC\_hour-C-FWK-BMA-EDR-2-Zone-C;UCa;20210  
20170127085959;AC\_hour-C-FWK-BMA-EDR-2-Zone-C;RM;45020  
[...]

**Cut line with** : %{DATA:date}[;]%{DATA:name\_compt}[;]%{DATA:Application}[;]%{INT:volume}

**Logstash's conf is :**

```
filter {
if [type] == "q_compt" {
 grok {
 match => { "message" => "%{DATA:date}[;]%{DATA:nom_compt}[;]%{DATA:Application}[;]%{INT:volume}" }
}

date {
 match => ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
  }
 }
}

```

My aim is to create Kibana's Graph with this datas but why ?

**I would like 3 graphs (3 applications), with data volume associated**. (Be careful, the graph must respect the data at head of each line to stay consistent)

Can you see do to what i want ?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 27, 2017, 4:19pm UTC](https://discuss.elastic.co/t/create-consistent-graph-in-kibana/73025/2 "2017-01-27T16:19:26Z")

</div>

Did you already manage to ingest your data using the logstash configuration you quoted? If yes, then you should easily be able to create a [line chart](https://www.elastic.co/guide/en/kibana/current/line-chart.html) on the index pattern that matches your data. To have a separate chart for each application you can split the buckets by `Terms`:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/855e5e0e271c31f285216da426dba6800ab78abd.png)

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [February 6, 2017, 9:23am UTC](https://discuss.elastic.co/t/create-consistent-graph-in-kibana/73025/3 "2017-02-06T09:23:56Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/2X/c/c6eee1d6fb7bce467a5a475374b63ea372535fa4.png)

Y-Axis : The Fields is offset only ..

Split Chart : Aggregation on Terms give fields on screenshot attachment.

Why ? 😢

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [February 6, 2017, 10:38am UTC](https://discuss.elastic.co/t/create-consistent-graph-in-kibana/73025/4 "2017-02-06T10:38:55Z")

</div>

Ok to Split lines is good (I refresh my index pattern Filebeat).

**But to Y-Axis when I choose Sum than aggregation i havven't any Field available (just offset)**

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [February 6, 2017, 2:04pm UTC](https://discuss.elastic.co/t/create-consistent-graph-in-kibana/73025/5 "2017-02-06T14:04:04Z")

</div>

Most aggregations only work on numeric fields. That means that the during ingestion the relevant data have to be indexed with one of the appropriate [numeric types](https://www.elastic.co/guide/en/elasticsearch/reference/current/number.html). The Logstash configuration above looks like using `%{NUMBER:volume}` should achieve that. See the [grok filter documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) for more patterns.

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [February 6, 2017, 4:00pm UTC](https://discuss.elastic.co/t/create-consistent-graph-in-kibana/73025/7 "2017-02-06T16:00:49Z")

</div>

Ok I change my pattern from

{ "message" =\> "%{DATA:date}[;]%{DATA:nom\_compt}[;]%{DATA:Application}[;]%{ **INT** :volume}" }

to

{ "message" =\> "%{DATA:date}[;]%{DATA:nom\_compt}[;]%{DATA:Application}[;]%{ **NUMBER** :volume}" }

But any change in Kibana. When i want configure my Y-Axis .. Always the offset only.

![](https://us1.discourse-cdn.com/elastic/original/2X/d/d40f76558c782b139efa4a3f2a9642c2ea1bc380.png)

When I Go in parameter's field, i have 2 fields Applications :

- volume (not aggregatable)
- volume.keywords (aggregatable)

![](https://us1.discourse-cdn.com/elastic/original/2X/1/14537430e875f3f222d69d041405134e363df804.png)

I don't understand where it's bloked

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [February 8, 2017, 10:23am UTC](https://discuss.elastic.co/t/create-consistent-graph-in-kibana/73025/8 "2017-02-08T10:23:24Z")

</div>

In order for the changes to take effect, some or all of the following might be necessary:

1. Restart Logstash to apply the new configuration.
2. Delete the Elasticsearch index that contains the old mapping, in which the `volume` field is of type string. Existing field mappings can not be changed after an index has been created.
3. Click the "Reload" icon in the Kibana index pattern management screen to tell Kibana to re-read the mappings.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2017, 10:23am UTC](https://discuss.elastic.co/t/create-consistent-graph-in-kibana/73025/9 "2017-03-08T10:23:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
