# Dashboard : display the sum of several counts

**URL:** <https://discuss.elastic.co/t/dashboard-display-the-sum-of-several-counts/123883>\
**Category:** Kibana\
**Created:** [March 14, 2018, 10:40am UTC](https://discuss.elastic.co/t/dashboard-display-the-sum-of-several-counts/123883 "2018-03-14T10:40:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Florent\_Fauvin](https://avatars.discourse-cdn.com/v4/letter/f/d2c977/32.png) [@Florent\_Fauvin](https://discuss.elastic.co/u/Florent_Fauvin)\
**Post date:** [March 14, 2018, 10:40am UTC](https://discuss.elastic.co/t/dashboard-display-the-sum-of-several-counts/123883/1 "2018-03-14T10:40:52Z")

</div>

Hello,

I would like to display in my dashboard the sum of several counts.

For example, today, my search returns the authentication errors for SSH :

_result: "authentication failure" =\> count:3_  
_result: "Authentication FailureS" =\> count:5_  
_result: "authentication failed" =\> count:1_

I would like to display in my dashboard a line chart representing _"Authentication errors"_ which is the sum of counts above.  
For today, _"Authentication errors":9_ (9=3+5+1)

How can I do that ? Is it possible ?

Feel free to ask me more information if you wish,

Thank you for your help,

Florent

---

<div class="post-metadata">

**Author:** ![lfroment-datasweet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lfroment-datasweet/32/32908_2.png) [@lfroment-datasweet](https://discuss.elastic.co/u/lfroment-datasweet)\
**Post date:** [March 14, 2018, 12:58pm UTC](https://discuss.elastic.co/t/dashboard-display-the-sum-of-several-counts/123883/2 "2018-03-14T12:58:44Z")

</div>

Hi Florent,

that should be possible in several ways, depending on how your data is stored in ES. Are your 3 results stored in the same field?

result: "authentication failure" =\> count:3  
result: "Authentication FailureS" =\> count:5  
result: "authentication failed" =\> count:1

As I suspect, you are french speaking, maybe we can arrange a private chat so that I can clearly understand what can be done.

---

<div class="post-metadata">

**Author:** ![Florent\_Fauvin](https://avatars.discourse-cdn.com/v4/letter/f/d2c977/32.png) [@Florent\_Fauvin](https://discuss.elastic.co/u/Florent_Fauvin)\
**Post date:** [March 14, 2018, 3:46pm UTC](https://discuss.elastic.co/t/dashboard-display-the-sum-of-several-counts/123883/3 "2018-03-14T15:46:13Z")

</div>

"As I suspect, you are french speaking"

> Oh shame ! Yes I am 🙂 !!!

"Are your 3 results stored in the same field?"

> No. There is one result tag for one syslog log.

"maybe we can arrange a private chat so that I can clearly understand what can be done."

> Yes Ok. How can we do that?

Florent !

---

<div class="post-metadata">

**Author:** ![Florent\_Fauvin](https://avatars.discourse-cdn.com/v4/letter/f/d2c977/32.png) [@Florent\_Fauvin](https://discuss.elastic.co/u/Florent_Fauvin)\
**Post date:** [March 14, 2018, 4:28pm UTC](https://discuss.elastic.co/t/dashboard-display-the-sum-of-several-counts/123883/4 "2018-03-14T16:28:38Z")

</div>

I bring details below:

I have different servers which have different error messages for SSH syslog logs.  
When I parse there logs and fill a _"result"_ field, I get different messages for the _"result"_ field :

_result: "Failed password"_  
_result: "authentication error"_  
_result: "authentication failure"_  
_result: "authentication failures"_  
_etc._

**My goal is to display a line chart "SSH errors".**  
=\> So, I would like to sum the counts of these different error results in a common count.

Is it possible ??

Florent !

---

<div class="post-metadata">

**Author:** ![Florent\_Fauvin](https://avatars.discourse-cdn.com/v4/letter/f/d2c977/32.png) [@Florent\_Fauvin](https://discuss.elastic.co/u/Florent_Fauvin)\
**Post date:** [March 20, 2018, 5:27pm UTC](https://discuss.elastic.co/t/dashboard-display-the-sum-of-several-counts/123883/5 "2018-03-20T17:27:28Z")

</div>

SOLUTION :

Mon erreur était de sélectionner dans X-Axis : Aggregation/Terms:result

La solution est donc de faire une recherche sur les terms de result que l'on veut aggréger, puis de visualiser sur X-Axis : Aggregation/date Histogram:@timestamp

Merci à lfroment-datasweet - Lionel Froment !!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2018, 5:27pm UTC](https://discuss.elastic.co/t/dashboard-display-the-sum-of-several-counts/123883/6 "2018-04-17T17:27:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
