# How to add two fields using Timelion?

**URL:** <https://discuss.elastic.co/t/how-to-add-two-fields-using-timelion/124147>\
**Category:** Kibana\
**Created:** [March 15, 2018, 5:08pm UTC](https://discuss.elastic.co/t/how-to-add-two-fields-using-timelion/124147 "2018-03-15T17:08:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [March 15, 2018, 5:08pm UTC](https://discuss.elastic.co/t/how-to-add-two-fields-using-timelion/124147/1 "2018-03-15T17:08:27Z")

</div>

Hello,

I am trying to add the values of system.cpu.system.pct & system.cpu.user.pct and get the total cpu usage for this particular server.

I have the following query:

```auto
(.es(index=metricbeat-*, q='beat.hostname:server1', timefield='@timestamp', metric='sum:system.cpu.system.pct').label(system.cpu.system.pct).multiply(100), .es(index=metricbeat-*, q='beat.hostname:server1', timefield='@timestamp', metric='sum:system.cpu.user.pct').multiply(100).label(system.cpu.user.pct))(.sum(.es()).label('Total CPU'))

```

I am expecting to see the total cpu usuage to be around 15% or so, but i am getting this huge graph of 1750000.

Actual values :

# system.cpu.system.pct - 5.28%

# system.cpu.user.pct - 0.101

Please see screenshots.

This graph shows the values for the two fields

 ![Graph1](https://us1.discourse-cdn.com/elastic/original/3X/8/4/848215197f5917810d7c75daaf9cff8d507d475b.PNG)

This should be the result of adding the above fields.

 ![Total](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b185e461d8d7c6a7a7b1f5808c449ea8d776597a.PNG)

Thanks for the help!

-Mock

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [March 15, 2018, 7:13pm UTC](https://discuss.elastic.co/t/how-to-add-two-fields-using-timelion/124147/2 "2018-03-15T19:13:25Z")

</div>

@thomasneirynck/@timroes any ideas?

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [March 15, 2018, 7:26pm UTC](https://discuss.elastic.co/t/how-to-add-two-fields-using-timelion/124147/3 "2018-03-15T19:26:21Z")

</div>

hi @cchooks2,

That .sum looks to be in an odd spot.

> [@cchooks2](#):
>
> (.sum(.es()).label('Total CPU'))

You would do something like:

.es(...first-series..).sum(.es(...second-series....))

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [March 15, 2018, 7:29pm UTC](https://discuss.elastic.co/t/how-to-add-two-fields-using-timelion/124147/4 "2018-03-15T19:29:06Z")

</div>

First let me ask: is there a specific reason, you are not simply visualizing the [`system.cpu.total.pct`](https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fields-system.html#_literal_system_cpu_total_pct_literal) field instead? 🙂

The rest is as Thomas mentioned.

---

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [March 16, 2018, 4:46am UTC](https://discuss.elastic.co/t/how-to-add-two-fields-using-timelion/124147/5 "2018-03-16T04:46:15Z")

</div>

@thomasneirynck,

Thanks for the info ... my new query is:

```auto
 .es(index=metricbeat-*, q='beat.hostname:server1', timefield='@timestamp', metric='sum:system.cpu.system.pct').label(system.cpu.system.pct).multiply(100), .es(index=metricbeat-*, q='beat.hostname:server1', timefield='@timestamp', metric='sum:system.cpu.user.pct').label(system.cpu.user.pct).multiply(100), .es(index=metricbeat-*, q='beat.hostname:server1', timefield='@timestamp', metric='sum:system.cpu.system.pct').multiply(100).sum(.es(index=metricbeat-*, q='beat.hostname:server1', timefield='@timestamp', metric='sum:system.cpu.user.pct').multiply(100)).label('Total CPU')

```

Which is working now.

Thanks

---

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [March 16, 2018, 4:47am UTC](https://discuss.elastic.co/t/how-to-add-two-fields-using-timelion/124147/6 "2018-03-16T04:47:56Z")

</div>

@timroes,

So this system.cpu.total.pct field will give me the total cpu used? I do not see this field as part of the available fields. We are using Metricbeat 5.5.

Will I need to divide it by the number of cores i have to get the actual cpu usage?

Thanks.

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [March 19, 2018, 4:58pm UTC](https://discuss.elastic.co/t/how-to-add-two-fields-using-timelion/124147/7 "2018-03-19T16:58:51Z")

</div>

Hi Steven,

yeah that metric wasn't available in 5.5, but is available in more recent versions.

You can divide by the number of cores if you want a number between 0 to 100%, but I would say the actual CPU usage in a unix world is specified as 0.0 to 4.0 (if you have 4 cores). So I would totally get what 2.6 (or 260%) means if I see that, but that might be depending on your personal preferences 🙂

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2018, 4:58pm UTC](https://discuss.elastic.co/t/how-to-add-two-fields-using-timelion/124147/8 "2018-04-16T16:58:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
