# Displaying difference of sum of two values

**URL:** https://discuss.elastic.co/t/displaying-difference-of-sum-of-two-values/119097
**Category:** Kibana
**Created:** [February 8, 2018, 5:47pm UTC](https://discuss.elastic.co/t/displaying-difference-of-sum-of-two-values/119097 "2018-02-08T17:47:00Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![divyaharshan](https://avatars.discourse-cdn.com/v4/letter/d/43a26b/32.png) [@divyaharshan](https://discuss.elastic.co/u/divyaharshan)
#### Post date: [February 8, 2018, 5:47pm UTC](https://discuss.elastic.co/t/displaying-difference-of-sum-of-two-values/119097/1 "2018-02-08T17:47:00Z")

</div>

I have a dataset loaded in the below csv format

time, totalnumber, correctnumber, location

I need to do a query similar to below sql

select sum(totalnumber)- sum(correctnumber) group by time, location

Is this possible in elastic search kibana, I am currently have a scripted field Totalnumber-currentnumber and am currently displaying SUM of this in a line graph split by location and time.  
But it would really help if I can display sum(totalnumber)- sum(correctnumber)

---

<div class="post-metadata">

### Author: ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)
#### Post date: [February 8, 2018, 6:39pm UTC](https://discuss.elastic.co/t/displaying-difference-of-sum-of-two-values/119097/2 "2018-02-08T18:39:25Z")

</div>

Easiest way to do this would be in Timelion.

Just create a chart with this function:  
`.es(*,metric='sum:totalnumber').subtract(.es(*,metric='sum:correctnumber')`

---

<div class="post-metadata">

### Author: ![divyaharshan](https://avatars.discourse-cdn.com/v4/letter/d/43a26b/32.png) [@divyaharshan](https://discuss.elastic.co/u/divyaharshan)
#### Post date: [February 8, 2018, 6:56pm UTC](https://discuss.elastic.co/t/displaying-difference-of-sum-of-two-values/119097/3 "2018-02-08T18:56:10Z")

</div>

Is there a way to group this is timelion for me it would be like difference  
at a particular time for a particular location.

---

<div class="post-metadata">

### Author: ![DidierB](https://avatars.discourse-cdn.com/v4/letter/d/ed8c4c/32.png) [@DidierB](https://discuss.elastic.co/u/DidierB)
#### Post date: [February 13, 2018, 4:38pm UTC](https://discuss.elastic.co/t/displaying-difference-of-sum-of-two-values/119097/4 "2018-02-13T16:38:52Z")

</div>

I would like to do this kind of thing but term by term, something like:

average(user.t2 - user.t1)  
and not  
average(user.t2) - average(user.t1)

is there a way to do it?

---

<div class="post-metadata">

### Author: ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)
#### Post date: [February 13, 2018, 9:38pm UTC](https://discuss.elastic.co/t/displaying-difference-of-sum-of-two-values/119097/5 "2018-02-13T21:38:43Z")

</div>

Are user.t1 and user.t2 present in every document? If so, then average(user.t2 - user.t1) will be the same as average(user.t2) - average(user.t1)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 13, 2018, 9:39pm UTC](https://discuss.elastic.co/t/displaying-difference-of-sum-of-two-values/119097/6 "2018-03-13T21:39:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
