# Difference of aggregated value that grouped by two fields across time

**URL:** <https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906>\
**Category:** Kibana\
**Created:** [November 1, 2022, 2:46pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906 "2022-11-01T14:46:02Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![amylyu](https://avatars.discourse-cdn.com/v4/letter/a/a3d4f5/32.png) [@amylyu](https://discuss.elastic.co/u/amylyu)\
**Post date:** [November 1, 2022, 2:46pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906/1 "2022-11-01T14:46:02Z")

</div>

Hi, we are getting data into elastic through Kafka Prometheus endpoint and trying to create a visualization which would help us show latest ingestion rate in each kafka topics. In order to achieve this, we need to group by two fields – partitions & topic name. Since this value is incremental, we also need to calculate the difference between the value we are getting now – aggregated value we had one minute before. The purpose of this calculation is to get realtime data ingestion rate/topic. Is there a way in kibana to create this kind of visualization? Thank you in advance!

We are using Elasticsearch version 7.16.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [November 3, 2022, 4:17pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906/2 "2022-11-03T16:17:01Z")

</div>

The solution for the ingest rate is using the "Serial difference" aggregation in the classic aggregation types and TSVB, or the "Differences" formula in Lens. And the grouping is available everywhere, just add a second one after the first one.

---

<div class="post-metadata">

**Author:** ![amylyu](https://avatars.discourse-cdn.com/v4/letter/a/a3d4f5/32.png) [@amylyu](https://discuss.elastic.co/u/amylyu)\
**Post date:** [November 3, 2022, 4:38pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906/3 "2022-11-03T16:38:54Z")

</div>

Thanks for replying! I have tried using the TSVB, but I can only group by one terms. There is no way I can add the second "group by".

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [November 3, 2022, 4:40pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906/4 "2022-11-03T16:40:20Z")

</div>

Click the + button next to the "By" where you select the field. That should add another selector the second field.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [November 3, 2022, 4:41pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906/5 "2022-11-03T16:41:04Z")

</div>

![groupby](https://us1.discourse-cdn.com/elastic/original/3X/e/b/eb82b3e96f0a3a36e00ce748cd4def2a76121d89.png)

---

<div class="post-metadata">

**Author:** ![amylyu](https://avatars.discourse-cdn.com/v4/letter/a/a3d4f5/32.png) [@amylyu](https://discuss.elastic.co/u/amylyu)\
**Post date:** [November 3, 2022, 4:57pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906/6 "2022-11-03T16:57:00Z")

</div>

![Screen Shot 2022-11-03 at 12.55.49 PM](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b7075b4d841b13ccea1956f90fe214a7e0fa65e6.png)  
There is no + button. Is this due to the version of Elasticsearch?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [November 3, 2022, 5:16pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906/7 "2022-11-03T17:16:53Z")

</div>

it could be, it's been added in 8.2.0. you can upgrade or use Lens instead.

---

<div class="post-metadata">

**Author:** ![amylyu](https://avatars.discourse-cdn.com/v4/letter/a/a3d4f5/32.png) [@amylyu](https://discuss.elastic.co/u/amylyu)\
**Post date:** [November 3, 2022, 5:50pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906/8 "2022-11-03T17:50:25Z")

</div>

If I use Lens by the line chart, how can I aggregate by two terms? I can break down by one field, but I failed to break down by another one.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 1, 2022, 4:26pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906/9 "2022-12-01T16:26:51Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2022, 4:27pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906/10 "2022-12-29T16:27:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
