# Extract Metricbeat network traffic visualization DSL query

**URL:** <https://discuss.elastic.co/t/extract-metricbeat-network-traffic-visualization-dsl-query/226837>\
**Category:** Elasticsearch\
**Created:** [April 7, 2020, 7:13am UTC](https://discuss.elastic.co/t/extract-metricbeat-network-traffic-visualization-dsl-query/226837 "2020-04-07T07:13:10Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mudboyzh](https://avatars.discourse-cdn.com/v4/letter/m/c68b51/32.png) [@Mudboyzh](https://discuss.elastic.co/u/Mudboyzh)\
**Post date:** [April 7, 2020, 7:13am UTC](https://discuss.elastic.co/t/extract-metricbeat-network-traffic-visualization-dsl-query/226837/1 "2020-04-07T07:13:10Z")

</div>

I want to understand how does the metricbeat's network traffic visualization DSL query.

I had already used the Chrome Dev Tools to get the DSL query and the Kibana saved object, but the request payload and visState seems only for Kibana.

 ![截圖 2020-04-07 下午2.41.33](https://us1.discourse-cdn.com/elastic/original/3X/6/8/689db0df85bc6ac43fdb1091fbce90953978a45a.png)

There are few aggregations in the visualization.

I tried to transform it into DSL, but I not sure about the aggs layer  
is it right or not. Apparently I lost some aggs.

I don's see the document about "Positive Only Agg" and "Series Agg".  
I don't know how to use it correctly in DSL.

Here is my DSL:

```auto
GET metricbeat-*/_search
{
  "size": 0,
  "query": {
    "bool": {
      "must_not": [
        {
          "term": {
            "system.network.name": "l*"
          }
        }
      ], 
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "now-1m"
            }
          }
        }
      ]
    }
  },
  "aggs": {
    "time": {
      "date_histogram": {
        "field": "@timestamp",
        "interval": "second",
        "min_doc_count": 1
      },
      "aggs": {
        "max_out": {
          "max": {
            "field": "system.network.out.bytes"
          }
        },
        "max_out_deriv": {
          "derivative": {
            "buckets_path": "max_out"
          }
        }
      }
    },
    "sum_of_deriv": {
      "sum_bucket": {
        "buckets_path": "time>max_out"
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2020, 7:13am UTC](https://discuss.elastic.co/t/extract-metricbeat-network-traffic-visualization-dsl-query/226837/2 "2020-05-05T07:13:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
