# Graph calculated value

**URL:** <https://discuss.elastic.co/t/graph-calculated-value/57961>\
**Category:** Kibana\
**Created:** [August 12, 2016, 9:56pm UTC](https://discuss.elastic.co/t/graph-calculated-value/57961 "2016-08-12T21:56:43Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jerry\_Hoffmeister](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@Jerry\_Hoffmeister](https://discuss.elastic.co/u/Jerry_Hoffmeister)\
**Post date:** [August 12, 2016, 9:56pm UTC](https://discuss.elastic.co/t/graph-calculated-value/57961/1 "2016-08-12T21:56:43Z")

</div>

Pretty sure I can't do this but wanted to ask... I have data that I want to graph field x / field y rather than just graphing field x over time. Can I do this in kibana or do I have to calculate the value using a logstash filter or something?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [August 12, 2016, 10:07pm UTC](https://discuss.elastic.co/t/graph-calculated-value/57961/2 "2016-08-12T22:07:24Z")

</div>

If the values are numbers, I believe you could use a scripted field to do this. Something like this aught to work for the script:

`doc['fieldA'].value / doc['fieldB'].value`

You'll find scripted fields under the Indices settings, it's a tab above the field list.

EDIT: Of course, this will show the computed value over time, which now that I read your question again, doesn't sound like what you want.

---

<div class="post-metadata">

**Author:** ![Jerry\_Hoffmeister](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@Jerry\_Hoffmeister](https://discuss.elastic.co/u/Jerry_Hoffmeister)\
**Post date:** [August 12, 2016, 10:09pm UTC](https://discuss.elastic.co/t/graph-calculated-value/57961/3 "2016-08-12T22:09:35Z")

</div>

The data is actually disk bytes used and in the same doc, I have the capacity and I'd like to graph the %used instead of just the raw bytes used. I'm using nagioscheckbeat to get the data to ES. And not all docs in the index have the same fields - some are just heartbeat records for example.

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [August 12, 2016, 10:25pm UTC](https://discuss.elastic.co/t/graph-calculated-value/57961/4 "2016-08-12T22:25:16Z")

</div>

> [@Jerry\_Hoffmeister](#):
>
> The data is actually disk bytes used and in the same doc, I have the capacity and I'd like to graph the %used instead of just the raw bytes used.

Over time? If so, then this should give you that value in percent minus the % symbol:

`doc['bytes_used'].value / doc['total_bytes'].value * 100`

Or, you can use the Percentage field formatter on that scripted field to handle both the decimal move as well as the % symbol. If you go that route, just remove the `* 100` bit.

> [@Jerry\_Hoffmeister](#):
>
> And not all docs in the index have the same fields - some are just heartbeat records for example.

I assume you are indexing these documents as different types then. In which case, you can just filter on the `_type` to get at the data you need.

Let me know if I'm way off base here, but it sounds like this should give you what you want based on what I think you're asking.

---

<div class="post-metadata">

**Author:** ![Jerry\_Hoffmeister](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@Jerry\_Hoffmeister](https://discuss.elastic.co/u/Jerry_Hoffmeister)\
**Post date:** [August 12, 2016, 10:27pm UTC](https://discuss.elastic.co/t/graph-calculated-value/57961/5 "2016-08-12T22:27:49Z")

</div>

thanks - lemme try... \_type for the metrics data is always nagiosmetric but the individual metrics have a different "name" - the name field in this case is "disks". I assume I can work with that...

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [August 12, 2016, 10:47pm UTC](https://discuss.elastic.co/t/graph-calculated-value/57961/6 "2016-08-12T22:47:02Z")

</div>

Yup, that would work too. As long as you can filter on some field value that's unique to the records you care about, you should be set.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/graph-calculated-value/57961/7 "2017-07-06T13:41:11Z")

</div>


