# How do you show all data in X-Pack Graph?

**URL:** <https://discuss.elastic.co/t/how-do-you-show-all-data-in-x-pack-graph/110365>\
**Category:** Elasticsearch\
**Created:** [December 5, 2017, 1:39pm UTC](https://discuss.elastic.co/t/how-do-you-show-all-data-in-x-pack-graph/110365 "2017-12-05T13:39:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![I\_like\_dogs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/i_like_dogs/32/24384_2.png) [@I\_like\_dogs](https://discuss.elastic.co/u/I_like_dogs)\
**Post date:** [December 5, 2017, 1:39pm UTC](https://discuss.elastic.co/t/how-do-you-show-all-data-in-x-pack-graph/110365/1 "2017-12-05T13:39:52Z")

</div>

I want to visualize my honeypot data by showing the source IP connection to destination port. Not necessarily for analysis or drill downs, just for a visualization. I want to show all connections for all source IP's and all ports. Is there a query that can show the entire network?

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [December 6, 2017, 8:05pm UTC](https://discuss.elastic.co/t/how-do-you-show-all-data-in-x-pack-graph/110365/2 "2017-12-06T20:05:06Z")

</div>

Graph was designed to find non-obvious relationships in data so I don't think there's really a way to use it to show all connections. The only suggestion I have is to go into the Graph settings and try changing the `Certainty` from the default value of 3 down to 1 and see if that shows more relationships (but still may not show all).

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [December 11, 2017, 10:06am UTC](https://discuss.elastic.co/t/how-do-you-show-all-data-in-x-pack-graph/110365/3 "2017-12-11T10:06:25Z")

</div>

> [@I\_like\_dogs](#):
>
> Is there a query that can show the entire network?

Yes, but you'll need to tweak some settings - see the 3 suggestions here: [Graph Troubleshooting | Kibana User Guide [6.0] | Elastic](https://www.elastic.co/guide/en/kibana/6.0/graph-troubleshooting.html#_why_are_results_missing)

In addition, it is worth noting that if you have a lot of data that the graph analysis is performed on a sample of the data. While that sample could be large it might not represent all of the data and could just be dominated by records from only one pair of vertices (e.g. an IP address hitting port 80 10 million times). This would give a graph with only 2 vertices. To ensure your samples aren't dominated by a chatty pair you should use the _diversification_ feature to look across many communicating pairs in your example. This will give better coverage and more vertices on-screen. I would recommend diversifying on a `keyword` field that contains a communicating pairs' IDs, sorted e.g. the value `A->B` would cover all docs where A called B or B called A. An example script to build that sort if index is [here](https://gist.github.com/markharwood/c478ea0192857b9cdb24ad41d4d14fcd).

The settings in the Kibana GUI would look something like this:

 ![Kibana](https://us1.discourse-cdn.com/elastic/original/3X/7/5/757ec8d4043858d4135e98d025e3329d37ecf68e.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 10:06am UTC](https://discuss.elastic.co/t/how-do-you-show-all-data-in-x-pack-graph/110365/4 "2018-01-08T10:06:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
