# Daily dashboard with metrics from the last document

**URL:** <https://discuss.elastic.co/t/daily-dashboard-with-metrics-from-the-last-document/339963>\
**Category:** Kibana\
**Tags:** vega\
**Created:** [August 2, 2023, 6:00pm UTC](https://discuss.elastic.co/t/daily-dashboard-with-metrics-from-the-last-document/339963 "2023-08-02T18:00:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gueri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gueri/32/103243_2.png) [@gueri](https://discuss.elastic.co/u/gueri)\
**Post date:** [August 2, 2023, 6:00pm UTC](https://discuss.elastic.co/t/daily-dashboard-with-metrics-from-the-last-document/339963/1 "2023-08-02T18:00:23Z")

</div>

Hello

I'm trying to use Vega as a new tool for me in Kibana. I read some basics tutorials and tried some examples with my editor. It is a powerfull tool !

I already used Kibana lens charts for networks logs with billions of documents. But I also retrieve from Elastic some homemade metrics logs with document format like this :

```auto
"_source" : {
  "count" : {
    "proc_1" : {
      "Server" : {
        "total" : 100
        "system_a" : 80
        "system_b" : 20
      },
      "BackupSite" : {
        "total" : 4
        "sys_c" : 3
        "sys_d" : 1
      }
    },
    "proc_2" : {
      "Server" : {
        "total" : 102
        "system_a" : 82
        "system_b" : 20
      },
      "BackupSite" : {
        "total" : 4
        "sys_c" : 2
        "sys_d" : 2
      }
	}
  },
  "ids" : {
    "Server" : {
      "common" : 90
      "only_in_proc_1" : 2
      "only_in_proc_2" : 8
    },
    "BackupSite" : {
      "common" : 2
      "only_in_proc_1" : 1
      "only_in_proc_2" : 1
    }
  }
}

```

In fact there are many many metrics in one document and I get one document each day (maybe 2 somtimes).

I would like to do a "daily" dashboard to show some metrics and compare them between proc\_1 and proc\_2. In a normal way, count have to be identical and only\_in\_proc\_x have to be 0 or near zero.

I would like to use Vega to do this. So I define the data section to get only the last document of my\_index like this :

```auto
  data: {
    url: {
      %context%: true
      %timefield%: @timestamp
      index: my_index
      body: {
        "size": 1, 
        "sort": [
          {
            "@timestamp": {
              "order": "desc"
            }
          }
        ],
        "_source": [<metrics fieldname here>]
      }
    }
    format: {property: "hits.hits"}
  }

```

But now I don't know what to do next. In examples, I often see data like multiple logs with a text field (here a) and a numeric field (here b).

a basic use case here :

```auto
 "data": {
    "values": [
      {"a": "A", "b": 28},
      {"a": "B", "b": 55},
      {"a": "C", "b": 43}
    ]
  }
and encoding like this
{
    "x": {"field": "a", "type": "nominal"},
    "y": {"field": "b", "type": "quantitative"}
  }

```

But in my case I only have \<field\_name\> = \<field\_value\>. I don't know how I can define differents metrics on the x axis.

Suppose I want to display count.proc\_1.Server.total , count.proc\_2.Server.total and difference between count.proc\_1.Server.total and count.proc\_2.Server.total with bars chart.

How can I do this in Vega ? Thanks for your help.

gueri

---

<div class="post-metadata">

**Author:** ![gueri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gueri/32/103243_2.png) [@gueri](https://discuss.elastic.co/u/gueri)\
**Post date:** [August 2, 2023, 9:53pm UTC](https://discuss.elastic.co/t/daily-dashboard-with-metrics-from-the-last-document/339963/2 "2023-08-02T21:53:12Z")

</div>

Oh oh! Maybe I found a solution with the transform "fold"

```auto
{
  "$schema": "https://vega.github.io/schema/vega-lite/v5.json",
  "data": {
    "values": [
      {"country": "USA", "gold": 10, "silver": 20}
    ]
  },
  "transform": [{"fold": ["gold", "silver"]}],
  "mark": "bar",
  "encoding": {
    "x": {"field": "key", "type": "nominal"},
    "y": {"field": "value", "type": "quantitative"},
    "color": {"field": "key", "type": "nominal"}
  }
}

```

I will try with my data and let you know!

---

<div class="post-metadata">

**Author:** ![gueri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gueri/32/103243_2.png) [@gueri](https://discuss.elastic.co/u/gueri)\
**Post date:** [August 10, 2023, 4:06pm UTC](https://discuss.elastic.co/t/daily-dashboard-with-metrics-from-the-last-document/339963/3 "2023-08-10T16:06:18Z")

</div>

YES, Great! the FOLD transform was the solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2023, 4:07pm UTC](https://discuss.elastic.co/t/daily-dashboard-with-metrics-from-the-last-document/339963/4 "2023-09-07T16:07:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
