# Create visualization for sum of system.cpu.cores per host

**URL:** <https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595>\
**Category:** Kibana\
**Created:** [December 4, 2023, 9:37pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595 "2023-12-04T21:37:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![lpowers](https://avatars.discourse-cdn.com/v4/letter/l/258eb7/32.png) [@lpowers](https://discuss.elastic.co/u/lpowers)\
**Post date:** [December 4, 2023, 9:37pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595/1 "2023-12-04T21:37:30Z")

</div>

I'm trying to create a visualization for the total cores for each host and then sum them all up to get a count for each of our clusters. Is it possible?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 5, 2023, 3:24am UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595/2 "2023-12-05T03:24:17Z")

</div>

Sure ... What version are you on?

You certainly should be able to create a number of different types of visualizations for

This assumes there is a label for the "cluster" which you can sum / agregrate on.

Perhaps provide a bit more information on what and how you are collecting the data.

Something like this is by cluster.

 ![Screenshot 2023-12-04 at 7.44.30 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f3ee37b98e0445ca34a4a548835c6189f067a80.png)

this is by host

 ![Screenshot 2023-12-04 at 7.46.35 PM](https://us1.discourse-cdn.com/elastic/original/3X/a/f/af7b1c6fc7b52a58f325bd553ceb8759d6d9f3e3.png)

---

<div class="post-metadata">

**Author:** ![lpowers](https://avatars.discourse-cdn.com/v4/letter/l/258eb7/32.png) [@lpowers](https://discuss.elastic.co/u/lpowers)\
**Post date:** [December 5, 2023, 7:00pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595/3 "2023-12-05T19:00:44Z")

</div>

How do you create a label? I was able to get per host using the visualization you provided but not for the entire cluster as I'm not sure how to label. We are on version 8.8.1.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 5, 2023, 7:30pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595/4 "2023-12-05T19:30:41Z")

</div>

How are you collecting the metrics?

Metricbeat / Elastic Agent? on your K8s Cluster? If so the cluster metadata should be picked up.

I am not sure if that exact metric widget is in 8.8 I think it is ... you will need to check.

If these are some sort of custom cluster you will need to add a field in metricbeat or agent.

---

<div class="post-metadata">

**Author:** ![lpowers](https://avatars.discourse-cdn.com/v4/letter/l/258eb7/32.png) [@lpowers](https://discuss.elastic.co/u/lpowers)\
**Post date:** [December 5, 2023, 9:44pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595/5 "2023-12-05T21:44:56Z")

</div>

Metricbeat and what we want to do is get the sum for the last value for each compute node in the cluster. I'm able to get the number of cores per compute using the last value for system.cpu.cores but, I don't know how to get the sum of them all. I tried to edit the formula and use "sum(last\_value(system.cpu.cores, kql='system.cpu.cores: \*'))" and it didn't work. Is this possible?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5b8d06fdec0c0adec5be719ef001c8200231822d.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 6, 2023, 1:05am UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595/6 "2023-12-06T01:05:27Z")

</div>

You don't you just take out the `Break down by` Field...

If you want both `Break down by` host and total, you will need to do 2 separate viz or a table with a Sum

 ![Screenshot 2023-12-05 at 5.09.17 PM](https://us1.discourse-cdn.com/elastic/original/3X/0/7/0761144e16d4c7204948e86b91c3aaa205450f21.jpeg)

---

<div class="post-metadata">

**Author:** ![lpowers](https://avatars.discourse-cdn.com/v4/letter/l/258eb7/32.png) [@lpowers](https://discuss.elastic.co/u/lpowers)\
**Post date:** [December 12, 2023, 5:17pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595/7 "2023-12-12T17:17:22Z")

</div>

Thanks! That helps. But, what do we do if we have thousands of documents that don't have system.cpu.cores set and it shows '-' in the visualization?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 12, 2023, 5:23pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595/8 "2023-12-12T17:23:46Z")

</div>

Well only the docs with that will be included... BUT if you really want to be sure... and it is not a bad idea.

In the KQL bar at the top will filter to only include those documents that contain

`system.cpu.cores: *`

or

`metricset.name : cpu`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2024, 5:23pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595/9 "2024-01-09T17:23:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
