# Display aggregated counter value per interval

**URL:** <https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333>\
**Category:** Kibana\
**Created:** [May 6, 2021, 7:08pm UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333 "2021-05-06T19:08:24Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![snicoll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snicoll/32/20285_2.png) [@snicoll](https://discuss.elastic.co/u/snicoll)\
**Post date:** [May 6, 2021, 7:08pm UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333/1 "2021-05-06T19:08:24Z")

</div>

I have two counters for open and closes issues, something like this:

```auto
timpestamp: epoch_mill1, total: 2000, open: 200, closed: 1800
timpestamp: epoch_mill2, total: 2200, open: 250, closed: 1950
timpestamp: epoch_mill3, total: 2300, open: 150, closed: 2150
timpestamp: epoch_mill4, total: 2500, open: 200, closed: 2300

```

I'd like to display a line chart that shows how much were open and closed on a given period. For instance, number of issues created per month.

I've built a line chart that uses the Average aggregation and I can see a chart that keeps increasing (makes sense). I've tried to add a date histogram aggregation but I haven't managed to make it work.

Thanks!

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [May 7, 2021, 1:25am UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333/2 "2021-05-07T01:25:52Z")

</div>

Maybe this can help

> [@Line chart with date histogram, split series and filter](https://discuss.elastic.co/t/line-chart-with-date-histogram-split-series-and-filter/221804):
>
> Hi, It seems clear to me that I'm obviously misunderstanding how filters are used in Kibana's visualizations and/or am using them incorrectly. Brief background. Each document contains a unique identifier and let's say two additional fields 'infectious contact'.keyword 'lhd'.keyword I create a Y axis and use a unique count of the unique identifier (which really I suppose wouldn't have to be unique). I then create buckets and split series as per below screenshot …

---

<div class="post-metadata">

**Author:** ![snicoll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snicoll/32/20285_2.png) [@snicoll](https://discuss.elastic.co/u/snicoll)\
**Post date:** [May 7, 2021, 7:30am UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333/3 "2021-05-07T07:30:26Z")

</div>

I don't know. I haven't made progress based on that thread though.

---

<div class="post-metadata">

**Author:** ![snicoll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snicoll/32/20285_2.png) [@snicoll](https://discuss.elastic.co/u/snicoll)\
**Post date:** [June 2, 2021, 6:57am UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333/4 "2021-06-02T06:57:01Z")

</div>

So I've made good progress using Lens and Last Value. What I am not able to do is find a way to compute the "spread". In the example above, 500 issues we created (2500 - 2000) and 500 issues where closed (2300 - 1800). What I'd like is a visualization that allow me to display that: a metric (for the whole vizualization) or a bar chart (to show that value per month, week, etc).

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [June 4, 2021, 4:18pm UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333/5 "2021-06-04T16:18:43Z")

</div>

We're working on a custom formula feature that I think might help out. Can you take a look at this unreleased screenshot and see if that's what you're trying to do? This is doing the difference between the two last\_value aggregations in the report and visualizing it against time as bars.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/a/caddf14b545e09c0b5e523f9c4e1dab7a12a09ee.png)

edit: or are you trying to compute how many issues got created. i.e. last\_value from the previous period compared to the same value from the current period.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/2/c20a871a157b8f9eb1b52e608fd3e394a3fe5a43.png)

---

<div class="post-metadata">

**Author:** ![snicoll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snicoll/32/20285_2.png) [@snicoll](https://discuss.elastic.co/u/snicoll)\
**Post date:** [June 5, 2021, 4:49pm UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333/6 "2021-06-05T16:49:59Z")

</div>

Thanks for sharing that @ghudgins.

What I am after is a way to compute the spread, i.e. the difference between the max and min value for a field. Showing a dashboard on the last year, for instance, would give me a metric of how much issues were created, in total for that period. The formula is to take the max value (last\_value) minus the min value (the first value of the period of interest).

In a similar fashion, I'd like to "bucket" that aggregation. Taking the example above, that would be a bar chart where each bar represents the number of issues that were opened per month (or per week, etc).

Back to your example, I am not looking at computing the difference between open and closed but rather the difference between the "max open" and "min open" for the period. Once I understand how to do this, I could apply it to other fields (such as number of closed issues).

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 5, 2021, 5:56pm UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333/7 "2021-06-05T17:56:21Z")

</div>

Hi @snicoll

Just driving by.... 🙂

What you are describing are counters (monotonically increasing numbers) so try counter rate in Lens . Very common in infra monitoring.

In order to get a rate (Open / Hour, Day Month) you have to take a derivative that is available in lens as the Function : Counter rate.

Counter rate will show you the rate of them per bucket like 1,000 per week open

So Try  
Lens  
Counter Rate

You will need to probably add different series because your total, open and closed are in different fields. This should be pretty straight forward. I am not sure the Normalized goes up to months

If you need more control in TSVB there is a counter rate as well that has some more flexibility for the normalized by function

 ![Screen Shot 2021-06-05 at 10.46.46 AM](https://us1.discourse-cdn.com/elastic/original/3X/4/4/441be05e63fd3d3746393dedd63c3e67394846ba.png)

If you feel that is not what you want you can also look at the Difference Function which will Calculate the difference period over period but will nor be normailzed over time. For differences I would us Difference of Max perhaps.

Give it a try ... let us know.

---

<div class="post-metadata">

**Author:** ![snicoll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snicoll/32/20285_2.png) [@snicoll](https://discuss.elastic.co/u/snicoll)\
**Post date:** [June 7, 2021, 6:30am UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333/8 "2021-06-07T06:30:00Z")

</div>

Thanks counter rate helped but the aggregation goes to a day max. What I'd like to do is build a dashboard over the last year (for instance) and get a bar graph where each bar represents a month and shows the number of created issues that month (one bar) and the number of closed issues that month (another bar next to it). I guess using a formula for this should work? It's a math operation between the first and the last value in the bucket...

Ideally this should be dynamic the same way Kibana does for a bunch of things. So if you show a few years, that would be by quarter or something.

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [June 7, 2021, 1:34pm UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333/9 "2021-06-07T13:34:33Z")

</div>

there's an actionable request for Kibana in your response, so I logged this enhancement. [[Lens] Additional normalize by unit counter rate interval options · Issue #101483 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/101483)

the dynamic aspect of your request is also something to ponder (as a user changes the scale of their dashboard intervals such as these update too)

thanks for reaching out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2021, 1:35pm UTC](https://discuss.elastic.co/t/display-aggregated-counter-value-per-interval/272333/10 "2021-07-05T13:35:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
