# Fleet : Visualizing Synthetic logs

**URL:** <https://discuss.elastic.co/t/fleet-visualizing-synthetic-logs/292835>\
**Category:** Elastic Observability\
**Tags:** fleet\
**Created:** [December 23, 2021, 5:00pm UTC](https://discuss.elastic.co/t/fleet-visualizing-synthetic-logs/292835 "2021-12-23T17:00:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [December 23, 2021, 5:00pm UTC](https://discuss.elastic.co/t/fleet-visualizing-synthetic-logs/292835/1 "2021-12-23T17:00:33Z")

</div>

Hello,

I added a synthetics integration and I can see the Uptime monitor but I want to create a visualization with this data. How can I easily select the data I want to show?

I'm trying to add different filters to isolate the datastream type and name without success.

Thanks

---

<div class="post-metadata">

**Author:** ![abdulz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdulz/32/97601_2.png) [@abdulz](https://discuss.elastic.co/u/abdulz)\
**Post date:** [December 29, 2021, 1:28pm UTC](https://discuss.elastic.co/t/fleet-visualizing-synthetic-logs/292835/2 "2021-12-29T13:28:49Z")

</div>

Hi @Gustavo_Llermaly,

Apologies for the belated reply. Please have a look on the feature [Exploratory data visualizations](https://www.elastic.co/guide/en/observability/current/exploratory-data-visualizations.html) and see if this is what you are looking for.

In the upcoming releases, data shown in Uptime will have even more links to the Exploratory View, which will visualize only one or more metrics of that monitor, while also allowing the user to add more series.

Let us know if you have further questions.

---

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [December 29, 2021, 2:23pm UTC](https://discuss.elastic.co/t/fleet-visualizing-synthetic-logs/292835/3 "2021-12-29T14:23:41Z")

</div>

Thanks Abdul,

I'm having a hard time trying to generate heartbeat visualizations outisde Uptime view because as you know we only need to grab the last event sort by @timestamp to know the current status.

The exploration data visualizations link is very useful but it doesnt include the chart that mentions if the monitor is up or down only. How can I generate this one to put it in my dashboard?

Thanks

---

<div class="post-metadata">

**Author:** ![abdulz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdulz/32/97601_2.png) [@abdulz](https://discuss.elastic.co/u/abdulz)\
**Post date:** [January 3, 2022, 9:31pm UTC](https://discuss.elastic.co/t/fleet-visualizing-synthetic-logs/292835/4 "2022-01-03T21:31:01Z")

</div>

I see your point @Gustavo_Llermaly. In some of the other charts, we do provide "Open in Lens" link to open a particular chart in [Lens](https://www.elastic.co/kibana/kibana-lens) where that visualization can then be customized and added to a dashboard. I'll create an enhancement request to have that link for "Pings over time" chart in Uptime as well.

However, to recreate the "Pings over time" visualization for a particular monitor (or monitors if that's desired) should be fairly simple in Lens. I am summarizing the steps below:

1. Find the Monitor ID from Uptime monitor details page.
2. Goto Lens and choose the **heartbeat-** \* (or **synthetics-** \* in newer versions) index.
3. Filter records by desired `monitor.id` and `synthetics.type : "heartbeat/summary"` as we are only interested in those records containing "up" and "down" statuses.
4. Drag `@timestamp` field into Lens. Adjust the time range if needed.
5. Drag `monitor.status` onto right sidebar of Lens under **Break down by** section.
6. You should now have the "Pings over time" visualization recreated.
7. When happy with the result, save the visualization.

If changing the series colors are desired, that can also be done. The following two screencasts demonstrates how that can be done. The first screencast repeats what is mentioned above. The second demonstrates how to have more granular series with custom colors and names.

How to re-create "Pings over time" chart:

[![](https://us1.discourse-cdn.com/elastic/original/3X/9/d/9d927bb572c5fe825286732f8a0c2753456a11c2.jpeg "Elastic Kibana - How to recreate Uptime "Pings over time" chart") ](https://www.youtube.com/watch?v=-qU3uSxA_GM)

How to customize series and colors:

[![](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a72eb0c87ad18c44946022ad0264c49a3582ab6.jpeg "Elastic Kibana - How to color pings-over-time chart") ](https://www.youtube.com/watch?v=w7Oqwqnn8w8)

Hope that helps, do let us know if you need further help.

---

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [January 6, 2022, 10:46pm UTC](https://discuss.elastic.co/t/fleet-visualizing-synthetic-logs/292835/5 "2022-01-06T22:46:19Z")

</div>

Thanks @abdulz !! awesome explanation. in your example is better to use filters instead of the searchbar to filter the documents or is the same?

---

<div class="post-metadata">

**Author:** ![abdulz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdulz/32/97601_2.png) [@abdulz](https://discuss.elastic.co/u/abdulz)\
**Post date:** [January 11, 2022, 3:15pm UTC](https://discuss.elastic.co/t/fleet-visualizing-synthetic-logs/292835/6 "2022-01-11T15:15:30Z")

</div>

As far filtering monitors is concerned (on the Uptime page), whichever brings you the desired monitors in the list, works. Applying filters is handy if you are looking for monitors of specific type or monitors testing a port, for instance. So, in this case it's the same whether you zero in on the concerning monitor(s) by a text query or via filters.

To filter documents for visualizations (in Lens or other places), it's better NOT to use free style text searches.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:33am UTC](https://discuss.elastic.co/t/fleet-visualizing-synthetic-logs/292835/7 "2022-11-04T08:33:33Z")

</div>


