# How to build charts from Elasticsearch query

**URL:** https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697
**Category:** Elasticsearch
**Created:** [July 5, 2016, 8:41am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697 "2016-07-05T08:41:45Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)
#### Post date: [July 5, 2016, 8:41am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697/1 "2016-07-05T08:41:45Z")

</div>

I have a command which is able to run in Elasticsearch following something similar to [Moving average aggregation | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-movavg-aggregation.html#_prediction)

> GET linux\_cpu\*/\_search?search\_type=count  
> {  
> "aggs": {  
> "my\_date\_histo": {  
> "date\_histogram": {  
> "field": "@timestamp",  
> "interval": "day"  
> },  
> "aggs": {  
> "the\_sum": {  
> "avg": {  
> "field": "CPU(%)"  
> }  
> },  
> "the\_movavg": {  
> "moving\_avg": {  
> "bucketsPath": "the\_sum",  
> "window": 90,  
> "model": "holt\_winters",  
> "settings": {  
> "type": "add",  
> "alpha": 0.8,  
> "beta": 0.2,  
> "gamma": 0.7,  
> "period": 30  
> },  
> "predict": 30  
> }  
> }  
> }  
> }  
> }  
> }

However, I don't know how can I generate a graph based on the query. Could anyone help with this?

---

<div class="post-metadata">

### Author: ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)
#### Post date: [July 5, 2016, 8:57am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697/2 "2016-07-05T08:57:06Z")

</div>

Hi @Kennedy_Kan1,

that is out of scope of Elasticsearch and it depends entirely on your use case. A popular option is to use [Kibana](https://www.elastic.co/products/kibana) for that but you could also use the R connector and visualize your data there, write custom application logic etc. etc..

Daniel

---

<div class="post-metadata">

### Author: ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)
#### Post date: [July 5, 2016, 9:10am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697/3 "2016-07-05T09:10:31Z")

</div>

Hi @danielmitterdorfer,

Thanks for your replies. However, as seen from the html, it did output some graph. I have captured one here.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/ecc332785ce9948a89463b1da0b8ae89a3b2bd4c.png)

**How should I be able to do that?**

I have already tried to use Timelion with moving average function but it seems could not give something even similar/

---

<div class="post-metadata">

### Author: ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)
#### Post date: [July 5, 2016, 9:22am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697/4 "2016-07-05T09:22:56Z")

</div>

Hi @Kennedy_Kan1,

it seems I have misunderstood your question. I thought you wanted to know how to generate charts at all based on a query result. I think your question is better suited for the Kibana forum if you already use Kibana. Could you post your question there?

Daniel

---

<div class="post-metadata">

### Author: ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)
#### Post date: [July 5, 2016, 9:26am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697/5 "2016-07-05T09:26:15Z")

</div>

Hi @danielmitterdorfer,

Sure, however, it seems that this function is used as an ES query but not as a kibana query. Therefore, I thought there are some packages to generate the graph for special query. How is that possible to make ES to ship this query to kibana?

---

<div class="post-metadata">

### Author: ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)
#### Post date: [July 5, 2016, 9:28am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697/6 "2016-07-05T09:28:56Z")

</div>

Hi @Kennedy_Kan1,

it is actually the other way around. When you create a visualization in Kibana, you build an Elasticsearch query which Kibana issues against Elasticsearch and then visualizes the results. So, you don't start with an Elasticsearch query, but with a visualization and build the query via the Kibana UI.

Daniel

---

<div class="post-metadata">

### Author: ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)
#### Post date: [July 5, 2016, 9:35am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697/7 "2016-07-05T09:35:06Z")

</div>

Hi @danielmitterdorfer,

Thanks for clarifying my misunderstanding. Nevertheless, I have some questions towards my queries in ES.

As stated in question of my query, I wish to predict 30 days data. I have data input from 2014-12-31 to 2015-05-31, a 15-second basis record for CPU value and I use day as interval here in ES query.  
However, when I go through the date start from 2015-06-01, it gives me the following

```
       {
      "key_as_string": "2015-05-30T00:00:00.000Z",
      "key": 1432944000000,
      "doc_count": 96,
      "the_sum": {
        "value": 5
      },
      "the_movavg": {
        "value": 4.789703098153141
      }
    }, "key_as_string": "2015-06-01T00:00:00.000Z",
  "key": 1433116800000,
  "doc_count": 0,
  "the_sum": {
    "value": null
  }
},
{
  "key_as_string": "2015-06-02T00:00:00.000Z",
  "key": 1433203200000,
  "doc_count": 0,
  "the_sum": {
    "value": null
  }
},

```

Is that an error or is that normal for ES?

---

<div class="post-metadata">

### Author: ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)
#### Post date: [July 5, 2016, 9:53am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697/8 "2016-07-05T09:53:49Z")

</div>

Hi,

bear with me. I'll need a bit of time to check this.

Daniel

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 5, 2016, 10:03am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697/9 "2016-07-05T10:03:22Z")

</div>

This directly relates to [How to use Kibana to run Elasticsearch query?](https://discuss.elastic.co/t/how-to-do-es-moving-avearge-prediction-with-logstash/54683).

Given you already have a thread open on this topic, let's keep the conversation there please 🙂

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 5, 2016, 10:03am UTC](https://discuss.elastic.co/t/how-to-build-charts-from-elasticsearch-query/54697/10 "2016-07-05T10:03:25Z")

</div>


