# Cumulative sum of metrics of all entries passing query in Line Chart

**URL:** https://discuss.elastic.co/t/cumulative-sum-of-metrics-of-all-entries-passing-query-in-line-chart/55240
**Category:** Kibana
**Created:** [July 11, 2016, 9:56pm UTC](https://discuss.elastic.co/t/cumulative-sum-of-metrics-of-all-entries-passing-query-in-line-chart/55240 "2016-07-11T21:56:11Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![vtslac](https://avatars.discourse-cdn.com/v4/letter/v/ac91a4/32.png) [@vtslac](https://discuss.elastic.co/u/vtslac)
#### Post date: [July 11, 2016, 9:56pm UTC](https://discuss.elastic.co/t/cumulative-sum-of-metrics-of-all-entries-passing-query-in-line-chart/55240/1 "2016-07-11T21:56:11Z")

</div>

Hi all, I have a line chart in the format I already want that displays sum of metric for Disk I/O on 25 machines on our cluster that looks like this:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/ea0b37d81f282d9933edc194c589904e6e3f213b.png)

The query that generates this graph is of the form:  
`plugin:disk AND type:disk_octets AND (host:machine10* OR host:machine20* ...)`

Is there a way to convert this line chart into a cumulative sum, i.e., showing 1 line that is the sum of all the 25 values in each bin. Something that would show "total Disk I/O for the system" rather than on a per machine basis.

---

<div class="post-metadata">

### Author: ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)
#### Post date: [July 11, 2016, 10:30pm UTC](https://discuss.elastic.co/t/cumulative-sum-of-metrics-of-all-entries-passing-query-in-line-chart/55240/2 "2016-07-11T22:30:45Z")

</div>

I'm probably misunderstanding your question, but can't you just remove the bucket agg that's creating the split lines?

---

<div class="post-metadata">

### Author: ![vtslac](https://avatars.discourse-cdn.com/v4/letter/v/ac91a4/32.png) [@vtslac](https://discuss.elastic.co/u/vtslac)
#### Post date: [July 11, 2016, 10:41pm UTC](https://discuss.elastic.co/t/cumulative-sum-of-metrics-of-all-entries-passing-query-in-line-chart/55240/3 "2016-07-11T22:41:55Z")

</div>

Just figured this out too, with some other changes I was able to get the desired final result. Thanks!

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 13, 2016, 1:54am UTC](https://discuss.elastic.co/t/cumulative-sum-of-metrics-of-all-entries-passing-query-in-line-chart/55240/4 "2016-07-13T01:54:22Z")

</div>

Can you share your solution, it might help others in the future! 🙂

---

<div class="post-metadata">

### Author: ![vtslac](https://avatars.discourse-cdn.com/v4/letter/v/ac91a4/32.png) [@vtslac](https://discuss.elastic.co/u/vtslac)
#### Post date: [July 19, 2016, 10:17pm UTC](https://discuss.elastic.co/t/cumulative-sum-of-metrics-of-all-entries-passing-query-in-line-chart/55240/5 "2016-07-19T22:17:53Z")

</div>

Sure! The original query and formatting of the plot had the split-line aggregation, which once I removed resulted in plotting the cumulative sum of values in each bucket.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 1:45pm UTC](https://discuss.elastic.co/t/cumulative-sum-of-metrics-of-all-entries-passing-query-in-line-chart/55240/6 "2017-07-06T13:45:38Z")

</div>


