# Displaying time series in Canvas

**URL:** <https://discuss.elastic.co/t/displaying-time-series-in-canvas/279208>\
**Category:** Kibana\
**Created:** [July 20, 2021, 9:48pm UTC](https://discuss.elastic.co/t/displaying-time-series-in-canvas/279208 "2021-07-20T21:48:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gabor](https://avatars.discourse-cdn.com/v4/letter/g/8797f3/32.png) [@gabor](https://discuss.elastic.co/u/gabor)\
**Post date:** [July 20, 2021, 9:48pm UTC](https://discuss.elastic.co/t/displaying-time-series-in-canvas/279208/1 "2021-07-20T21:48:37Z")

</div>

Hi,

I have a data set based on some server logs containing sent- and received amount of data and client IPs. The dataset is a collection of these documents:  
`{ .. server_ip: IP1, client_ip: IP2, read: 2232323234, write: 232322, ...}`

Hopefully it's ok to ask 2 questions:

1. I'd like to create a Canvas text element displaying the number of distinct client\_ips. I tried something like "SELECT DISTINCT client\_ip from log" but apparently no "DISTINCT" support yet. (I'm running Kibana 7.12)

2. both the read and written fields' value is monotonically increasing, ie.: the total amount of data read/written up to that point. Is it possible to create another text element that counts up the used bandwith, ie.: for each client\_IP it finds the lowest and highest value of the read/write fields and divides by the time period.

Appreciate any insights.

Thanks,  
Gábor

---

<div class="post-metadata">

**Author:** ![corey.robertson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/corey.robertson/32/54611_2.png) [@corey.robertson](https://discuss.elastic.co/u/corey.robertson)\
**Post date:** [July 21, 2021, 2:34pm UTC](https://discuss.elastic.co/t/displaying-time-series-in-canvas/279208/2 "2021-07-21T14:34:26Z")

</div>

Hi @gabor

For question 1)  
You should be able to do the unique count via the expression, instead of essql.

Something like this

```auto
filters
| essql query="SELECT client_ip from log"
| ply by="client_ip" expression={head 1}
| rowCount 

```

For #2, I'm not sure I completely understand. I think I understand you want the highread - lowread for the total, but where does the time period come from?

---

<div class="post-metadata">

**Author:** ![gabor](https://avatars.discourse-cdn.com/v4/letter/g/8797f3/32.png) [@gabor](https://discuss.elastic.co/u/gabor)\
**Post date:** [July 21, 2021, 7:40pm UTC](https://discuss.elastic.co/t/displaying-time-series-in-canvas/279208/3 "2021-07-21T19:40:32Z")

</div>

Hi @corey.robertson,

Thans for the suggestion on q1; I do get this problem:

```auto
Whoops! Expression failed

Expression failed with the message:

[essql] > Unexpected error from Elasticsearch: [verification_exception] Found 1 problem line 1:8: SELECT DISTINCT is not yet supported

```

As I mentioned, I'm running Kibana 7.12

With regards to Q2, I'm happy to elaborate: so, I have these docs in my index, each representing a measurement. They are taken in ca. every 30s interval. I'm looking for the amount of data exchanged between server\_ip and client\_ip, measured by MBytes/sec in the arbitrarily selected "time period". Suppose doc1 and doc2 are the nearest to the start and end of this "time period". Both of these will have a read/write value. I'd like to visualize the average: (doc2.read - doc1.read) / (t2 - t1)

Does that make sense?

Thanks.

---

<div class="post-metadata">

**Author:** ![corey.robertson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/corey.robertson/32/54611_2.png) [@corey.robertson](https://discuss.elastic.co/u/corey.robertson)\
**Post date:** [July 21, 2021, 8:04pm UTC](https://discuss.elastic.co/t/displaying-time-series-in-canvas/279208/4 "2021-07-21T20:04:28Z")

</div>

Apologies for that error. You need to take `distinct` out of the query. I've edited my original response to correct it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2021, 8:05pm UTC](https://discuss.elastic.co/t/displaying-time-series-in-canvas/279208/5 "2021-08-18T20:05:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
