# Don't understand result of aggregation in table visualization

**URL:** <https://discuss.elastic.co/t/dont-understand-result-of-aggregation-in-table-visualization/157098>\
**Category:** Kibana\
**Created:** [November 16, 2018, 3:32pm UTC](https://discuss.elastic.co/t/dont-understand-result-of-aggregation-in-table-visualization/157098 "2018-11-16T15:32:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [November 16, 2018, 3:32pm UTC](https://discuss.elastic.co/t/dont-understand-result-of-aggregation-in-table-visualization/157098/1 "2018-11-16T15:32:32Z")

</div>

Hi folks,  
I'm using elastic stack 6.2.4.

I've build a dashboard to support the analysis of our loadtests. In the selected interval I am plotting 1st and last event timestamp, count of events + throughput. But I don't understand the results kibana is giving me, I expect much different results when I am doing the calculation in Excel.

I defined the first part of the aggregation like the following:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/1/51071f7af9882fb98a4e76082ccacef95bee008b.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/c/acec1495ea025f93fed8ab26a08dd137c96ea32f.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/35c05e4087879dc851ee6f4379d6d3502bf66484.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/8/985da65e2d8b4f937e9fe661070abc95ed9b1d6c.png)  
...  
**PLEASE klick on the images to see the full config. the forum is cutting of the buttom of the images in overview!**

The result looks like the following:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff9b5cd420fe784a400254c510485bfc3cd9df33.png)

I've selected following range in kibana: **2018-11-14 16:08:00.000** to **2018-11-14 16:40:37.312**

I know I first had a mind error, I hoped the throughput will be calculated based on min and max timestamp, but on 2nd thought kibana i am quite sure that kibana will take the time window set up in the dashboard.

Lets discuss the first line:  
My time window (selected in kibana is 32min and 37sec. That makes 1957 second. In this time we find 181053 events. But kibana tells me, that I have a throughput of 181053 per hour or 109 events per second. If I calculate the avg throughput per second I would calculate 181053 / 1957s = 92.55 events per second. That difference to 109 events per second is way too much to be an rounding issue.

What does kibana calculate or how can I get kibana to calculate it my way?  
Btw: If my loadtest is running over the hour change, kibana is dividing the avg count per hour by 2 - the number of involved hours.

Can anyone please shed some light?  
Thanks Andreas

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [November 19, 2018, 4:40pm UTC](https://discuss.elastic.co/t/dont-understand-result-of-aggregation-in-table-visualization/157098/2 "2018-11-19T16:40:47Z")

</div>

@asp, it's not entirely clear what you would like to see exactly. can you post an example of the table (from excell e.g.) of what your result should look like.

also, from your screenshot, it's not clear what aggregation you are exactly running. from the screenshot, we can only see the metrics you are computing for a given bucket.

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [November 21, 2018, 8:23am UTC](https://discuss.elastic.co/t/dont-understand-result-of-aggregation-in-table-visualization/157098/3 "2018-11-21T08:23:03Z")

</div>

Thanks for the reply.

That's why I added that comment to the thread:

> [@asp](#):
>
> PLEASE klick on the images to see the full config. the forum is cutting of the buttom of the images in overview!

If you klick on the screenshots you can see, that I am using a count metric and time bucket set Date histogram to hour, minute or second. From that Calculation I show the average Bucket.

Also interesting and curious. If I query the same time interval again, I have slightly different results.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fc02399495739fc53c923dec9184abd2ad19230a.png)

I would expect the following ( **excel sheet with GERMAN numeric notation. So you need to swap dot and comma in your mind** ):

| kibana time interval | 14.11.2018 16:08 | 14.11.2018 16:40 | | | | |
| --- | --- | --- | --- | --- | --- | --- |
| kibana interval time in sec | 1.957 | | | | | |
| | | | | | | |
| | | | count | count per hour | count per min | count per sec |
| 01 - TBM2 HighPrio Gwy to Tux | 2018-11-14 16:08:20.000 | 2018-11-14 16:40:12.000 | 181053 | 333.056,11 | 5.550,94 | 92,52 |
| 02 - NON-DTCO processing (tux queue empty) | 2018-11-14 16:08:21.000 | 2018-11-14 16:40:14.000 | 102964 | 189.407,46 | 3.156,79 | 52,61 |
| 03 - DTCO processing (tap\_dispatcher\_msg empty) | 2018-11-14 16:13:37.000 | 2018-11-14 16:38:28.000 | 79247 | 145.778,85 | 2.429,65 | 40,49 |

Formular: count / "kibana interval time in sec" = "count per sec"  
"count per min" = "count per sec" \* 60  
"count per hour = "count per sec" \* 3600

Original goal was to use min and max timestamp from the table for avg. calculation, but I think that is not possible with kibana.

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [December 12, 2018, 11:27am UTC](https://discuss.elastic.co/t/dont-understand-result-of-aggregation-in-table-visualization/157098/4 "2018-12-12T11:27:01Z")

</div>

@thomasneirynck  
Any update here?

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [January 2, 2019, 3:30pm UTC](https://discuss.elastic.co/t/dont-understand-result-of-aggregation-in-table-visualization/157098/5 "2019-01-02T15:30:54Z")

</div>

any news? additional questions?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 30, 2019, 3:30pm UTC](https://discuss.elastic.co/t/dont-understand-result-of-aggregation-in-table-visualization/157098/6 "2019-01-30T15:30:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
