# Help recovering and outputting ES response in the Vega Visualization

**URL:** <https://discuss.elastic.co/t/help-recovering-and-outputting-es-response-in-the-vega-visualization/132450>\
**Category:** Kibana\
**Created:** [May 18, 2018, 9:49am UTC](https://discuss.elastic.co/t/help-recovering-and-outputting-es-response-in-the-vega-visualization/132450 "2018-05-18T09:49:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jose\_Miguel\_Perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jose_miguel_perez/32/31365_2.png) [@Jose\_Miguel\_Perez](https://discuss.elastic.co/u/Jose_Miguel_Perez)\
**Post date:** [May 18, 2018, 9:49am UTC](https://discuss.elastic.co/t/help-recovering-and-outputting-es-response-in-the-vega-visualization/132450/1 "2018-05-18T09:49:38Z")

</div>

Hello, everyone

So, my problem comes when I try to recover the response from elastic in order to output it to a text mark. Here is my code.

```
  {
  $schema: https://vega.github.io/schema/vega/v3.json
  data: {
    name: values
    url: {
      index: logstash-*
      body: {
        aggs: {
          1: {
            sum: {
              script: {
                inline:
                  '''
                  if (doc['rule.level'].value >= 9 && doc['rule.level'].value <= 12) { 
                  return 0.34*17.129
                  } else if (doc['rule.level'].value >= 13) {
                  return 0.68*17.129
                  } else {
                  return 0
                  }
                  '''
                lang: painless
              }
            }
          }
        }
        stored_fields: ["*"]
        script_fields: {
          riskd: {
            script: {
              inline:
                '''
                if (doc['rule.level'].value >= 9 && doc['rule.level'].value <= 12) { 
                return 0.34*17.129
                } else if (doc['rule.level'].value >= 13) {
                return 0.68*17.129
                } else {
                return 0
                }
                '''
              lang: painless
            }
          }
          saved: {
            script: {
              inline:
                '''
                if(doc['rule.id'].value == "607") {
                  if (doc['data.data'].value == "5712" || doc['data.data'].value == "5720" || doc['data.data'].value == "5551" || doc['data.data'].value == "5710") {
                    return (17.129*0.64)+150 
                  }
                  else if (doc['data.data'].value == "31164" || doc['data.data'].value == "31165") {
                    return 1500+1387+(0.64*500000)
                  }
                  else if (doc['data.data'].value == "31105" || doc['data.data'].value == "31154") {
                    return 0.34*17.129
                  }
                  else {
                    return 0
                  }
                }
                else if (doc['rule.id'].value == "200501" || doc['rule.id'].value == "200601") {
                  return 33.25
                }
                else {
                  return 0
                }
                '''
              lang: painless
            }
          }
        }
        docvalue_fields: [
          @timestamp
          data.vulnerability.published
          data.vulnerability.updated
          syscheck.mtime_after
          syscheck.mtime_before
        ]
        query: {
          bool: {
            must: [
              {
                query_string: {
                  query: rule.level[9 TO 15]
                  analyze_wildcard: true
                  default_field: *
                }
              }
              {
                range: {
                  @timestamp: {gte: 1526627683964, lte: 1526631283964, format: "epoch_millis"}
                }
              }
            ]
            filter: []
            should: []
            must_not: []
          }
        }
      }
    }
    format: {property: "aggregations.1"}
  }
  marks: {
    type: text
    encode: {
      enter: {
        fill: {value: "#15b700"}
        text: { What do I write here??? }
        fontSize: {value: 72}
        align: {value: "center"}
      }
      hover: {
        opacity: {value: 0.5}
      }
    }
  }
} 

```

This is what VEGA\_DEBUG.view.data('values') outputs:

```
[{…}]
0:
  value: 58.23860000000001
  Symbol(vega_id): 5
  __proto__ : Object
length : 1
__proto__ : Array(0)

```

So I'm unable to output this "suma" result in the visualization. It appears nothing and I've tried many ways. I would really appreciate your support.

Best regards.

---

<div class="post-metadata">

**Author:** ![nyuriks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nyuriks/32/26171_2.png) [@nyuriks](https://discuss.elastic.co/u/nyuriks)\
**Post date:** [May 18, 2018, 2:35pm UTC](https://discuss.elastic.co/t/help-recovering-and-outputting-es-response-in-the-vega-visualization/132450/2 "2018-05-18T14:35:41Z")

</div>

@Jose_Miguel_Perez hi, you are almost there. A few changes:

- data and marks should be arrays, not objects. So just wrap them in square brackets - `[{...}]` instead of `{...}`. (it might work without this, but just in case)
- Add `from: {data:"values"}` to your text mark
- The `text` channel should be set to `text: { field: "value" }`
- You set opacity to 0.5 on hover, but you never reset it to 1. Add an `update` encode section with `opacity: { value: 1 }`
- Style - I wouldn't use digits as aggregate names, use some proper name instead of `"1"`. This is just a safety in case some random code interprets digit as a number, and not a string.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2018, 2:35pm UTC](https://discuss.elastic.co/t/help-recovering-and-outputting-es-response-in-the-vega-visualization/132450/3 "2018-06-15T14:35:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
