# Get a number und events per minute

**URL:** <https://discuss.elastic.co/t/get-a-number-und-events-per-minute/289217>\
**Category:** Elasticsearch\
**Tags:** eql-elastic-query-language\
**Created:** [November 15, 2021, 3:31pm UTC](https://discuss.elastic.co/t/get-a-number-und-events-per-minute/289217 "2021-11-15T15:31:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bitnapper](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bitnapper/32/96566_2.png) [@bitnapper](https://discuss.elastic.co/u/bitnapper)\
**Post date:** [November 15, 2021, 3:31pm UTC](https://discuss.elastic.co/t/get-a-number-und-events-per-minute/289217/1 "2021-11-15T15:31:23Z")

</div>

Hi,

I tried to figure out how many documents come in per minute. I coulnt find anything useful in stack monitoring so I tried with kibana and failed. I built a query giving me the documents from last 90 days but I cant figure out how to divide the count by 90\*24\*60 and display this number in a dashboard.

```auto
GET /filebeat-*,metricbeat-*,winlogbeat-*/_count
{
  "query": {
    "range": {
      "@timestamp": {
        "gte": "now-90d/d",
        "lt": "now/d"
      }
    }
  }
}

```

Can anyone give a hint?

Thanks.  
Thorsten

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 16, 2021, 11:51am UTC](https://discuss.elastic.co/t/get-a-number-und-events-per-minute/289217/2 "2021-11-16T11:51:38Z")

</div>

Hello Thorsten,

I think you want an aggregation:

```auto
GET /filebeat-*,metricbeat-*,winlogbeat-*/_search
{
  "aggs": {
    "last3months": {
      "date_histogram": {
        "field": "@timestamp",
        "fixed_interval": "90d"
      }
    }
  }
}

```

which returns:

```auto
{
  "aggregations" : {
    "last3months" : {
      "buckets" : [
        {
          "key_as_string" : "2021-07-02T00:00:00.000Z",
          "key" : 1625184000000,
          "doc_count" : 5820220
        },
        {
          "key_as_string" : "2021-09-30T00:00:00.000Z",
          "key" : 1632960000000,
          "doc_count" : 7098684
        }
      ]
    }
  }
}

```

Does this help?

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![bitnapper](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bitnapper/32/96566_2.png) [@bitnapper](https://discuss.elastic.co/u/bitnapper)\
**Post date:** [November 18, 2021, 2:49pm UTC](https://discuss.elastic.co/t/get-a-number-und-events-per-minute/289217/3 "2021-11-18T14:49:37Z")

</div>

Thank you. Its a better iplementation , so thats an improvement. Thanks. But It doesnt answer the question or I did not understand how it calculates the average amount of documents per minute.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 19, 2021, 3:57pm UTC](https://discuss.elastic.co/t/get-a-number-und-events-per-minute/289217/4 "2021-11-19T15:57:35Z")

</div>

Hi @bitnapper Do you know you can do this simply with a lens visualization?

Just Go To Lens, Pick your Index Pattern and do Horizontal Axis Timestamp and Vertical Count of Records

 ![Screen Shot 2021-11-19 at 7.52.48 AM](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c1298f98e10a8a992eeb23cd82ac861de5abded.jpeg)

Then jus go under Advanced and Normalize By Unit.

 ![Screen Shot 2021-11-19 at 7.53.04 AM](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8b9a4dc7d790ded8d541034004b587f4a1fbe1b3.jpeg)

 ![Screen Shot 2021-11-19 at 7.53.18 AM](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fc379ea288752d267a2604ac9ce4fe8180e8ba33.jpeg)

And there you have it!

 ![Screen Shot 2021-11-19 at 7.57.21 AM](https://us1.discourse-cdn.com/elastic/original/3X/7/8/789af8f838886eda114b7656958f33650fb888c1.jpeg)

You can turn it into a table too!

 ![Screen Shot 2021-11-19 at 7.58.15 AM](https://us1.discourse-cdn.com/elastic/original/3X/6/a/6ab56d599e44980b01a25cfca1037f9981a70f6b.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2021, 3:57pm UTC](https://discuss.elastic.co/t/get-a-number-und-events-per-minute/289217/5 "2021-12-17T15:57:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
