# Dec 19, 2022: \[EN\] Transform Your SLO Dashboards

**URL:** <https://discuss.elastic.co/t/dec-19-2022-en-transform-your-slo-dashboards/320953>\
**Category:** Advent Calendar\
**Tags:** transforms\
**Created:** [December 19, 2022, 10:36am UTC](https://discuss.elastic.co/t/dec-19-2022-en-transform-your-slo-dashboards/320953 "2022-12-19T10:36:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![json](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/json/32/4125_2.png) [@json](https://discuss.elastic.co/u/json)\
**Post date:** [December 19, 2022, 10:36am UTC](https://discuss.elastic.co/t/dec-19-2022-en-transform-your-slo-dashboards/320953/1 "2022-12-19T10:36:30Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7d63588d4e7918d10cbcca750ec96c38a7367278.png)

Kibana is a useful tool for monitoring applications and services to ensure they are operating within specified service level objectives. Service level indicators (SLIs) are measurable aspects of a service, such as error codes and latency. Service level objectives (SLOs) define how an application or service is expected to perform as measured by the SLIs, and in a way, set service uptime and availability goals. As logging and metrics data generated by applications grow, so do the demands on the Elasticsearch cluster for processing aggregations over SLI data.

If you have ever assembled an SLO dashboard for a highly dense metrics dataset, you might already know how taxing SLI visualizations backed by millions of events can be on a cluster as each dashboard visualization performs one or more aggregations against the backing indices. One such aggregation, for example, might show the number of HTTP errors grouped by response code over a specified time interval. Another might aggregate proxy logs to show backend request latency over time.

Enter Elasticsearch [Transforms](https://www.elastic.co/guide/en/elasticsearch/reference/current/transforms.html). Transforms can be used to pre-aggregate SLI metrics, such as HTTP response codes, for SLO dashboards. Transforms query over existing indices then write summarized data to smaller indices that can be used by visualizations, allowing for fast retrieval of aggregated data without searching against the entire dataset.

Here, we will show you how to set up and use a transform using the sample web logs provided in Kibana. The following was performed on **8.5.2** of the Elastic Stack running in [Elastic Cloud](https://www.elastic.co/cloud).

## Loading The Sample Data

1. Follow the [Kibana Quick Start guide](https://github.com/elastic/sdh-elasticsearch/issues/6763#issuecomment-1344180503) to add **sample web logs** data.
2. Use **Discover** to gain some familiarity with the web log data and fields.

## 1. Configuration

We will be creating a [pivot transform](https://www.elastic.co/guide/en/elasticsearch/reference/current/transform-overview.html#pivot-transform-overview).

1. Open the main menu, then **Stack Management \> Transforms \> Create Transform**.

2. Choose **Kibana Sample Data Logs** as the data source.

3. Be sure **Pivot** is selected.

4. Set **Group by** to `@timestamp`. Click the pencil icon and set the **Interval** to **1h**.

5. Next, we will define the aggregations we want to execute and send to the transform destination index. Click **Add an aggregation …** , then type `response` to filter the selection box. Click **filter(response)**.  

6. Fill in the filter aggregation property details provided in the table. Add a range query in the should boolean clause as shown below, then click **Apply**.

7. Continue adding three additional parent aggregations for _ **3xx** _, _ **4xx** _, and _ **5xx** _ response status codes. Be sure to select **Add an aggregation …** for each group of status codes.

8. Let's add one more aggregation for all response codes. Use a **value count** aggregation on the `response.keyword` field and name the aggregation `response.total`.

9. With our five aggregations grouped by date, the transform preview should contain six fields. The preview shows a sample of the data that will be indexed to the destination transform index when the transform executes. If the preview looks good, click **Next**.

## 2. Transform Details

1. Provide a name for the transform in the Transform ID box, an optional description, and a destination index.

2. Click **Next**.

3. Click **Create and start**.

## Transform Status

The **Transforms** management page should show the transform as started. Click the arrow next to the transform ID, and select **Stats** to check its progress.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/5/7564b904d833b28fa5e40274ab30c463441b2dee.jpeg)

## Visualizing

The aggregated transform data can now be used for visualizations. Open **Discover** and select the data view (aka, index pattern) for the transform destination index, then inspect a sample document. Be sure to set the time picker far enough back to view the data set.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/4/14c779b02cf62d2f57fa3d70c9838fbcc4400231.jpeg)

The web server was not very busy during the 12:00 hour, only serving 6 requests. A single Lens visualization can show the SLO target.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8aa7fdf7e2a032a91e2f7e091455416321bb4823.jpeg)

### Create A Visualization

Add a Lens visualization with the following configuration to a new or existing dashboard:

| Configuration | Values |
| --- | --- |
| Visualization type | Lens/Area |
| Data view | transform\_sli\_data\_log\_responses |
| Horizontal axis | **Functions:** Date histogram  
**Field:** @timestamp  
**Minimum interval:** 1h  
**Drop partial intervals:** disabled |
| Vertical axis (I) | **Success Rate \> Data Method:** Formula  
**Formula:** `(sum(response.2xx) + sum(response.3xx) + sum(response.4xx))/sum(response.total)`  
**Appearance \> Name:** Success Rate  
**Value format:** Percent |
| Vertical axis (II) | **Failure Rate \> Data Method:** Formula  
**Formula:** `sum(response.5xx)/sum(response.value_count)`  
 **Appearance \> Name:** Failure Rate  
 **Value format:** Percent |
| Reference lines | transform\_sli\_data\_log\_responses  
**Vertical left axis \> Method:** Static value  
**Reference line value:** `0.95`  
**Icon decoration:** Alert  
**Line:** 2px  
**Color:** #F70E0E |
| Left axis | **Axis title \> Custom**"Request Rate" |

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0ad2d56605fc7ef3ff2214b2c0f4a8ff5dd3e4e2.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/f/af1979d515421d7c502dc71fc956d6f81cafc38e.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/7/87777e99b63d0619775d89118e5aaa5fe097ac15.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/d/1da0646e7cb8013ee1d095044b9c51e4a67a7466.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/b/abbd4cd5785b114d7316ad60ecb0521000184836.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/6/46449c0d358c11897cbaddc1af456492cfbb2209.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/1/91aa1703e0e788c62d3d9443e2eb606373fe0fe8.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2023, 10:36am UTC](https://discuss.elastic.co/t/dec-19-2022-en-transform-your-slo-dashboards/320953/2 "2023-01-16T10:36:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
