# Creating a visualization: aggregate data over time

**URL:** <https://discuss.elastic.co/t/creating-a-visualization-aggregate-data-over-time/298075>\
**Category:** Kibana\
**Created:** [February 23, 2022, 7:31pm UTC](https://discuss.elastic.co/t/creating-a-visualization-aggregate-data-over-time/298075 "2022-02-23T19:31:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![4art4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/4art4/32/98919_2.png) [@4art4](https://discuss.elastic.co/u/4art4)\
**Post date:** [February 23, 2022, 7:31pm UTC](https://discuss.elastic.co/t/creating-a-visualization-aggregate-data-over-time/298075/1 "2022-02-23T19:31:20Z")

</div>

I am likely using the wrong terms... or I would have found this in my searching...

I am getting documents every day that list activity for objects. Eg:  
Day 1:

```auto
{
    objectOne: {
        countOfFirstAction: 3,
        countOfSecondAction: 1
    },
    objectTwo: {
        countOfFirstAction: 5,
        countOfSecondAction: 0
    }
}

```

Day 2:

```auto
{
    objectOne: {
        countOfFirstAction: 4,
        countOfSecondAction: 6
    },
    objectTwo: {
        countOfFirstAction: 3,
        countOfSecondAction: 2
    }
}

```

I want to build a graph that will show the change in number of actions over time. Something like a line graph with dates on the bottom, and the totals for 'FirstAction' and 'SecondAction' plotted for each day.

So:  
day 1 would show 'FirstAction' == '8', and 'SecondAction' == '1'  
day 2 would show 'FirstAction' == '7', and 'SecondAction' == '8'

This seems like it would be easy, but using the lens results in unexpected graphs.

---

<div class="post-metadata">

**Author:** ![Marta\_Bondyra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_bondyra/32/102122_2.png) [@Marta\_Bondyra](https://discuss.elastic.co/u/Marta_Bondyra)\
**Post date:** [February 23, 2022, 9:56pm UTC](https://discuss.elastic.co/t/creating-a-visualization-aggregate-data-over-time/298075/2 "2022-02-23T21:56:33Z")

</div>

Hello, Could you paste a screenshot of what you've created with Lens and what you're trying to achieve?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 24, 2022, 8:05am UTC](https://discuss.elastic.co/t/creating-a-visualization-aggregate-data-over-time/298075/3 "2022-02-24T08:05:48Z")

</div>

I'm not sure what you exactly want and screenshot will help us to answer correctly,

I suppose, however, you need [a runtime field](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime-mapping-fields.html).

Using Dev Tools:

```auto
PUT your_index/_mapping
{
  "runtime":{
    "FirstAction":{
      "type":"long",
      "script": {"source": "emit(doc['objectOne.countOfFirstAction'].value + doc['objectTwo.countOfFirstAction'].value )"}
    },
    "SecondAction":{
      "type":"long",
      "script": {"source": "emit(doc['objectOne.countOfSecondAction'].value + doc['objectTwo.countOfSecondAction'].value )"}
    }
  }
}

```

Then, you can use `FirstAction` and `SecondAction` in Lens.

Another way could be using [`copy_to`](https://www.elastic.co/guide/en/elasticsearch/reference/current/copy-to.html) parameter BEFORE indexing documents and use that field to aggregate & visualize.

---

<div class="post-metadata">

**Author:** ![4art4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/4art4/32/98919_2.png) [@4art4](https://discuss.elastic.co/u/4art4)\
**Post date:** [February 24, 2022, 8:20pm UTC](https://discuss.elastic.co/t/creating-a-visualization-aggregate-data-over-time/298075/4 "2022-02-24T20:20:46Z")

</div>

I was trying to obfuscate the real data in my example. When I was asked for a screen shot, I added the above data... more or less... and tried to reproduce the problem so that I could take a screenshot.

Turns out that what I mostly needed was:  
#1: for the vertical axis: Each 'action' should use the function "sum"  
#2: for the horizontal axis: Choose 'date histogram', and for the timestamp, choose 'customize time interval' to '1 days'.

Simple stuff really... but I was tripping over some overly complicated filtering, and missing the time interval option.

That said, your response was very enlightening. Ill put that in my back pocket for when I need it. Thank you.

 ![Screenshot 2022-02-24 141959](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8bb97bd1e5d9d3456811f815dd839ea393485f55.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2022, 8:21pm UTC](https://discuss.elastic.co/t/creating-a-visualization-aggregate-data-over-time/298075/5 "2022-03-24T20:21:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
