# Data format for graph

**URL:** <https://discuss.elastic.co/t/data-format-for-graph/58843>\
**Category:** Kibana\
**Tags:** elastic-stack-graph\
**Created:** [August 24, 2016, 4:02pm UTC](https://discuss.elastic.co/t/data-format-for-graph/58843 "2016-08-24T16:02:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![abasu](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@abasu](https://discuss.elastic.co/u/abasu)\
**Post date:** [August 24, 2016, 4:02pm UTC](https://discuss.elastic.co/t/data-format-for-graph/58843/1 "2016-08-24T16:02:58Z")

</div>

Hi, new user here, so excuse the basic question. How do I setup data to appear in graph format? Is there an example dataset you provide for better understanding.

For example, I am looking at the following dataset - [https://github.com/swissleaks/swiss\_leaks\_data/tree/master/ICIJ\_20140123](https://github.com/swissleaks/swiss_leaks_data/tree/master/ICIJ_20140123) and trying to visualize a graph but unable to. I see nodes, but no links to edges. Also, clicking on a node does not provide details about the node.

Thanks.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [August 24, 2016, 4:25pm UTC](https://discuss.elastic.co/t/data-format-for-graph/58843/2 "2016-08-24T16:25:54Z")

</div>

Hi Abasu,

> [@abasu](#):
>
> How do I setup data to appear in graph format?

If you're planning on using the Kibana Graph UI (and Kibana in general) then the typical advice is to index information so that the tokens used to represent the things you want to report on are:

1. Unambiguous
2. Readable  
So, as an example:

- Email addresses, hashtags or domain names work great without any changes
- Bank account numbers could ideally do with the customer name appended
- Customer names are not reliably unique and could ideally do with customer IDs attached

This is part of general preparation of content for analysis - computers want unique IDs but people want to read labels and if your indexed strings serve both purposes you avoid the cost of expensive joins at search time that can otherwise limit scalability.

So, the data you reference has a lot of IDs but lacks labels. Having come from the same people who provided OffshoreLeaks and PanamaPapers datasets I imagine it is a similar format and needs a similar labelling treatment. The PanamaPapers blog post [1] I wrote contains scripts to load this sort of data and index appropriately.

> [@abasu](#):
>
> I see nodes, but no links to edges

This blog post also describes the settings you need to turn on for this "forensics" type work as the default settings are more tuned for "wisdom of crowds" scenarios where edges only appear if enough docs/people assert there is a strong-enough relationship to draw out.

Hope this helps.

[1] [Using the Elastic Graph on Panama Papers Analysis | Elastic Blog](https://www.elastic.co/blog/using-elastic-graph-and-kibana-to-analyze-panama-papers)

---

<div class="post-metadata">

**Author:** ![abasu](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@abasu](https://discuss.elastic.co/u/abasu)\
**Post date:** [August 24, 2016, 4:50pm UTC](https://discuss.elastic.co/t/data-format-for-graph/58843/3 "2016-08-24T16:50:52Z")

</div>

Thanks for the link. However, does not provide a link to the exact data used or any manipulations done to it.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [August 24, 2016, 5:04pm UTC](https://discuss.elastic.co/t/data-format-for-graph/58843/4 "2016-08-24T17:04:59Z")

</div>

The link is [http://bit.ly/espanama](http://bit.ly/espanama)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/data-format-for-graph/58843/5 "2017-07-06T13:42:40Z")

</div>


