# Display total sum in Kibana Dashboards

**URL:** <https://discuss.elastic.co/t/display-total-sum-in-kibana-dashboards/238302>\
**Category:** Kibana\
**Created:** [June 23, 2020, 4:29pm UTC](https://discuss.elastic.co/t/display-total-sum-in-kibana-dashboards/238302 "2020-06-23T16:29:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sherrie](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@Sherrie](https://discuss.elastic.co/u/Sherrie)\
**Post date:** [June 23, 2020, 4:29pm UTC](https://discuss.elastic.co/t/display-total-sum-in-kibana-dashboards/238302/1 "2020-06-23T16:29:36Z")

</div>

The following are my log messages: These together with date and time are grouped under "message"

Read 24 records from duplicate error queue into database 30s, 39  
Read 22 records from duplicate error queue into database 30s, 22  
Read 31 records from duplicate error queue into database 30s, 21

In this, I’m filtering out using the string “duplicate error queue”. Say, it occurs 100 times. Is there any way in Kibana were we can sum up the number of records which is available ?  
i.e., for the above example, if we have 3 strings as “duplicate exceptions queue”, my search query should add (24+22+31=77) and provide me output as 3 strings “duplicate exceptions queue” found and the sum is 77.

Is there a way by which we can do this in Kibana ? Could you please let me know whether any option is available to sum up a particular string in Kibana ?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [June 24, 2020, 6:55am UTC](https://discuss.elastic.co/t/display-total-sum-in-kibana-dashboards/238302/2 "2020-06-24T06:55:22Z")

</div>

Hi

Are you looking for something like this (Table Visualisation embedded in an Dashboard)?

 ![Bildschirmfoto 2020-06-24 um 08.53.38](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d81bd43c47e1a9bf8bbb874276f95a8b1eb2eaa.png)

Do you have a possibility to parse your log messages before ingesting into Elasticsearch?

Thx & Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![Sherrie](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@Sherrie](https://discuss.elastic.co/u/Sherrie)\
**Post date:** [June 24, 2020, 7:59pm UTC](https://discuss.elastic.co/t/display-total-sum-in-kibana-dashboards/238302/3 "2020-06-24T19:59:40Z")

</div>

Yes, I'm looking for something like this only. How to we sum up the count here ?

If we have the below logs,

Read 24 records from duplicate error queue into database 30s, 39  
Read 22 records from duplicate error queue into database 30s, 22  
Read 31 records from duplicate error queue into database 30s, 21

We could get the count of string "duplicate error queue" easily as 3.

But I also want to sum the count of records read - in this case 24+22+31 = 77

Yes, these are pcf log messages; We could parse the messages via logstash.

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [June 25, 2020, 10:24am UTC](https://discuss.elastic.co/t/display-total-sum-in-kibana-dashboards/238302/4 "2020-06-25T10:24:32Z")

</div>

Step 1, I've been using the following test message, so you should use Logstash to extract the number of records:

```
POST /error-msg/_doc
{
  "message": "Read 24 records from duplicate error queue into database 30s",
  "records": 24 
}

POST /error-msg/_doc
{
  "message": "Read 22 records from duplicate error queue into database 30s",
  "records": 22 
}

POST /error-msg/_doc
{
  "message": "Read 32 records from duplicate error queue into database 30s",
  "records": 31 
}
```

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [June 25, 2020, 10:28am UTC](https://discuss.elastic.co/t/display-total-sum-in-kibana-dashboards/238302/5 "2020-06-25T10:28:36Z")

</div>

Step2 create a table visualization (Visualize / Create Visualization / Data Table) like this (Coming a count and a sum aggregation)

 ![Bildschirmfoto 2020-06-25 um 12.26.40](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8daebf615d1dcbf65a6d85646688ae5280b1fd93.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2020, 10:28am UTC](https://discuss.elastic.co/t/display-total-sum-in-kibana-dashboards/238302/6 "2020-07-23T10:28:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
