# How do I sum the result of an aggregation and present it in a table?

**URL:** https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352
**Category:** Kibana
**Tags:** lens
**Created:** [January 31, 2023, 2:50pm UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352 "2023-01-31T14:50:52Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![eeijlar](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@eeijlar](https://discuss.elastic.co/u/eeijlar)
#### Post date: [January 31, 2023, 2:50pm UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352/1 "2023-01-31T14:50:52Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4ea4d933e909c7f9253fa50d6eafbc6c3e8a4a0e.png)

I would like to take the results of this query, namely the values:  
3683  
3676  
3574  
3530  
3706  
3695  
3663  
3530  
3586  
3567  
Sum them together, which would give: 36210, and display them in a table. I can't seem to figure out the table piece. I have tried just doing a straight sum of `kubernetes.pod.cpu.usage.nanocores` but that gives a different result, as `kubernetes.pod.cpu.usage.nanocores` is not an average, it's just a point-in-time value. I need to get a sum of a set of accumulated averages. The table I have looks like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a60428a21ebad356c670663c587150e717f9da62.png)

I have also tried to just take the average, but then I need to multiply that by the number of pods. I can't seem to find a metric for that which works.

I am using Kibana 7.17.7

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [February 1, 2023, 2:56am UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352/2 "2023-02-01T02:56:05Z")

</div>

Which Exact VIZ is that...

You have to do what is known as a Series Agg - SUM

Under that first Average AGG and another Agg

Series Agg of type Sum of the Average above

That says Sum the Values for the Series and in this case the Series is the Value for Each Pod... for each Time Bucket i,e. add the values in each bucket to get a sum for each time bucket

Leave still the group by term `kubernetes.pod.name`

The Table Part in TSVB can be hard why don't you try the Line First...

---

<div class="post-metadata">

### Author: ![eeijlar](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@eeijlar](https://discuss.elastic.co/u/eeijlar)
#### Post date: [February 1, 2023, 8:18am UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352/3 "2023-02-01T08:18:02Z")

</div>

Hi Stephen,

Thanks for your reply! It's the Table of of the same visual:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/f/bf8b750a8f879c0795b01fc3edffcfe2c71ffdc3.jpeg)

I tried Overall Sum (there is no option for Sum to aggregate the previous collection). It still just shows the average:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/8/682842a90a0239cd474d3d053addc371d1e4effc.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0a4f06def04f613d91b016e343337aacb751f6ff.png)

I think because there is only now a single value to sum up. The individual buckets have been accumulated into a single value.

I can't use Series Agg:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/1/6147966d447490812781946784681f3e01823df9.png)

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [February 2, 2023, 4:16pm UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352/4 "2023-02-02T16:16:52Z")

</div>

So the non-table version would look like this, Yeah done think TSVB table is going to work...  
I think Lens Might, but I don't have a 7.17. to test with

 ![Screen Shot 2023-02-02 at 7.42.24 AM](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e589f93c14665f3a0f464148e4ce86848b0f9b24.png)

And here is just a metric that could be over the whole time frame or the last bucket

 ![Screen Shot 2023-02-02 at 8.10.10 AM](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e84608c51d44f216088dcc9b4730a60febe8f15b.png)

 ![Screen Shot 2023-02-02 at 8.10.16 AM](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2dc7a29c7e87fc303cf930021c0b9fa8ebc1f950.png)

---

<div class="post-metadata">

### Author: ![eeijlar](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@eeijlar](https://discuss.elastic.co/u/eeijlar)
#### Post date: [February 13, 2023, 1:40pm UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352/5 "2023-02-13T13:40:11Z")

</div>

Thanks for your help @stephenb That explains it. Lens will work but there is no option to do the manipulations I need using a Bucket Script.

---

<div class="post-metadata">

### Author: ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)
#### Post date: [February 13, 2023, 3:00pm UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352/6 "2023-02-13T15:00:01Z")

</div>

@eeijlar that bucket script seems quite easy to be translated into a Lens formula.

---

<div class="post-metadata">

### Author: ![eeijlar](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@eeijlar](https://discuss.elastic.co/u/eeijlar)
#### Post date: [February 17, 2023, 6:28pm UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352/7 "2023-02-17T18:28:23Z")

</div>

That one is straightforward but I have another one that I am not sure if I can do in Lens. I will look into it further. Thanks @Marco_Liberati🙇‍♂️

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 17, 2023, 6:28pm UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352/8 "2023-03-17T18:28:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
