# Graphs in Kibana

**URL:** <https://discuss.elastic.co/t/graphs-in-kibana/60010>\
**Category:** Kibana\
**Created:** [September 7, 2016, 5:26pm UTC](https://discuss.elastic.co/t/graphs-in-kibana/60010 "2016-09-07T17:26:36Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![deepak727](https://avatars.discourse-cdn.com/v4/letter/d/87869e/32.png) [@deepak727](https://discuss.elastic.co/u/deepak727)\
**Post date:** [September 7, 2016, 5:26pm UTC](https://discuss.elastic.co/t/graphs-in-kibana/60010/1 "2016-09-07T17:26:36Z")

</div>

Hi there,

I am using elk stack for log monitoring and visualization.

Now I am monitoring pfsense and freenas with collectd which ships logs to logstash and after that it goes to elasticsearch, every thing works perfect Except the traffic graphs.

In kibana when I searching for the particular interface for if\_octects or if\_packets it shows me the constant value which is the higher one in rx and tx columns, and because of that my visualization for the bandwidth is not perfect.

It seems that the rx and tx values for if\_octets or if\_packets are not resetting, it stuck to the higher value only even if the no traffice is passing trough the interfaces.

Can any one let me know what I am doing wrong and where, is it in collectd config or something with logstash or kibana ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 8, 2016, 5:38am UTC](https://discuss.elastic.co/t/graphs-in-kibana/60010/2 "2016-09-08T05:38:35Z")

</div>

You might want to move this post to the Kibana category to get the correct attention. It's more of a Kibana question than a Logstash one.

---

<div class="post-metadata">

**Author:** ![deepak727](https://avatars.discourse-cdn.com/v4/letter/d/87869e/32.png) [@deepak727](https://discuss.elastic.co/u/deepak727)\
**Post date:** [September 8, 2016, 4:29pm UTC](https://discuss.elastic.co/t/graphs-in-kibana/60010/3 "2016-09-08T16:29:03Z")

</div>

Hi

I did it....... thanks for the info......

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [September 8, 2016, 10:26pm UTC](https://discuss.elastic.co/t/graphs-in-kibana/60010/4 "2016-09-08T22:26:12Z")

</div>

> [@deepak727](#):
>
> In kibana when I searching for the particular interface for if\_octects or if\_packets it shows me the constant value which is the higher one in rx and tx columns

Can you expound on that a bit? I'm a screenshot or a sample of the data would be helpful.

---

<div class="post-metadata">

**Author:** ![deepak727](https://avatars.discourse-cdn.com/v4/letter/d/87869e/32.png) [@deepak727](https://discuss.elastic.co/u/deepak727)\
**Post date:** [September 9, 2016, 7:46pm UTC](https://discuss.elastic.co/t/graphs-in-kibana/60010/5 "2016-09-09T19:46:07Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/2X/5/51650589f044d18ba93d02d6bacac8ca3f795e6d.jpg)

Here is the attached kibana discover page screenshot.

I am using collectd on pfsense through that I am getting the logs as attached in the screenshot, as you can see there is static value only and this time there is no data passing through the interface, so technically it should show 0 but it is not showing that...... it seems that it is giving me the higher captured value on rx and tx field.

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [September 9, 2016, 10:58pm UTC](https://discuss.elastic.co/t/graphs-in-kibana/60010/6 "2016-09-09T22:58:09Z")

</div>

I'm not sure how collectd or pfsense work, but the values showing there are the values stored in elasticsearch. Maybe if you can share your collectd or pfsense configuration I could try to point out the issue?

---

<div class="post-metadata">

**Author:** ![deepak727](https://avatars.discourse-cdn.com/v4/letter/d/87869e/32.png) [@deepak727](https://discuss.elastic.co/u/deepak727)\
**Post date:** [September 10, 2016, 10:55am UTC](https://discuss.elastic.co/t/graphs-in-kibana/60010/7 "2016-09-10T10:55:01Z")

</div>

Hi Spalger

Thanks for the reply.

As you know that pfsense is based on Freebsd and mine bsd version is 10.3

I am collecting logs through collectd and below is config of my collecd.conf in pfsense.

Hostname "[ie.firewall.com](http://ie.firewall.com)"  
FQDNLookup true  
BaseDir "/var/db/collectd"  
PIDFile "/var/run/collectd.pid"  
PluginDir "/usr/local/lib/collectd"

LoadPlugin aggregation  
LoadPlugin cpu  
LoadPlugin df  
LoadPlugin disk  
LoadPlugin exec  
LoadPlugin interface  
LoadPlugin load  
LoadPlugin memory  
LoadPlugin network  
LoadPlugin processes  
LoadPlugin swap  
LoadPlugin uptime  
LoadPlugin syslog  
LoadPlugin threshold  
LoadPlugin tail  
\<Plugin "syslog"\>  
LogLevel info

\<Plugin "aggregation"\>  
  
Plugin "cpu"  
Type "cpu"  
GroupBy "Host"  
GroupBy "TypeInstance"  
CalculateSum true

\<Plugin "disk"\>  
Disk "/^gptid/"  
Disk "/^ada/"  
Disk "/^md/"  
Disk "/^pass/"  
IgnoreSelected true

\<Plugin "interface"\>  
Interface "lo0"  
Interface "ipfw0"  
Interface "pflog0"  
Interface "pfsync0"  
Interface "plip0"  
Interface "/^usbus/"  
IgnoreSelected true

 Instance "ha" WarningMax 10000000 Persist true Interesting false 

\<Plugin "df"\>  
Mountpoint "/"  
Mountpoint "/^/mnt//"

 Server "xxx.xxx.x.xxx" "xxxx" ReportRelative true

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:39pm UTC](https://discuss.elastic.co/t/graphs-in-kibana/60010/8 "2017-07-06T13:39:10Z")

</div>


