# How to create a graph from sum differences?

**URL:** https://discuss.elastic.co/t/how-to-create-a-graph-from-sum-differences/118268
**Category:** Kibana
**Created:** [February 2, 2018, 6:41pm UTC](https://discuss.elastic.co/t/how-to-create-a-graph-from-sum-differences/118268 "2018-02-02T18:41:44Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)
#### Post date: [February 2, 2018, 6:41pm UTC](https://discuss.elastic.co/t/how-to-create-a-graph-from-sum-differences/118268/1 "2018-02-02T18:41:44Z")

</div>

How do I create a graph from calculations?

I have an index of documents containing the following information:

- id
- begin\_event (keyword)
- end\_event (keyword)
- duration (float)

And here's an example of some of those docs as comma-delimited lines:  
101, CALC\_FOO\_BEGIN, CALC\_FOO\_END, 5.3  
102, CALC\_BAR\_BEGIN, CALC\_BAR\_END, 2.7  
103, CALC\_FOO\_BEGIN, CALC\_FOO\_END, 4.5  
104, CALC\_BAR\_BEGIN, CALC\_BAR\_END, 3.2

Now what I'd like to do is create a chart of all the time spent with the following formula:  
SUM(CALC\_FOO\_BEGIN/END event durations) - SUM(CALC\_BAR\_BEGIN/END event durations)

Although I've been successful creating charts for CALC\_FOO\_BEGIN/END duration sums and CALC\_BAR\_BEGIN/END duration sums, I don't know how to calculate the differences as shown above.

Any tips. Still a newbie but trying hard!

Thanks,  
John.

---

<div class="post-metadata">

### Author: ![a5a](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@a5a](https://discuss.elastic.co/u/a5a)
#### Post date: [February 2, 2018, 7:57pm UTC](https://discuss.elastic.co/t/how-to-create-a-graph-from-sum-differences/118268/2 "2018-02-02T19:57:37Z")

</div>

Hi John,

Can you share some screenshots of how you've created the duration sums as you have them currently? The more detail, the better, especially of the charts you've created and the settings for those charts.

What kind of chart are you looking to create for the difference-of-sums chart?

---

<div class="post-metadata">

### Author: ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)
#### Post date: [February 2, 2018, 11:56pm UTC](https://discuss.elastic.co/t/how-to-create-a-graph-from-sum-differences/118268/3 "2018-02-02T23:56:20Z")

</div>

I haven't created a pie chart yet, but that's the intention. In general, I have lots of docs that provide the duration (time) between 2 events on a specific resource id. I want to create a pie chart showing how the total time is split among the various events. Getting the pie chart slice for a specific pair of events marked in a single document seems simple enough. However, one of the slices will be a time difference between two pairs of events.

Here are the ordering of original events in index `events`:

```auto
<timestamp>, id, PRE_CALC_BEGIN, ...
<timestamp>, id,PRE_CALC_END
<timestamp>, id, CALC_FOO_BEGIN
... Other events
<timestamp>, id ,CALC_BAR_BEGIN
<timestamp>, id, CALC_BAR_END
... other events
<timestamp>, id, CALC_FOO_END

```

And I have another index `durations` with those event pairs of interest and a duration between events:

```auto
id, start_event, end_event, duration

```

The TOTAL time spent on the activity is from PRE\_CALC\_BEGIN --\> CALC\_FOO\_END

I want a pie chart with 3 slices totaling to 100%:

1. Percent of time spent between PRE\_CALC\_BEGIN --\> PRE\_CALC\_END
2. Percent of time spent between CALC\_BAR\_BEGIN --\> CALC\_BAR\_END
3. Percent of time spent in all other activities calculated as the time (CALC\_FOO\_BEGIN/END time - CALC\_BAR\_BEGIN/END time

Does that make more sense @a5a?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [February 5, 2018, 11:56pm UTC](https://discuss.elastic.co/t/how-to-create-a-graph-from-sum-differences/118268/4 "2018-02-05T23:56:46Z")

</div>

You'd be best off doing this prior to indexing, but you have a look at something like [How to calculate delta value](https://discuss.elastic.co/t/how-to-calculate-delta-value/107156/2)

---

<div class="post-metadata">

### Author: ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)
#### Post date: [February 6, 2018, 12:03am UTC](https://discuss.elastic.co/t/how-to-create-a-graph-from-sum-differences/118268/5 "2018-02-06T00:03:13Z")

</div>

I think you're suggesting that most calculation across fields or across documents is best done outside of Kibana. Is that a reasonable interpretation?

That's the purpose of the second index `durations` that contains the time deltas needed. And that would have been perfect except... now I realize that I need yet another field to calculate the difference between two event pairs for #3 above. In this case, I wish I understood aggregations and parent/child/sibling pipelines better. Those maybe could help?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [February 6, 2018, 12:08am UTC](https://discuss.elastic.co/t/how-to-create-a-graph-from-sum-differences/118268/6 "2018-02-06T00:08:57Z")

</div>

It's expensive to do this particular calculation in Kibana (which is really happening in Elasticsearch), so if you can do it before sending it to Elasticsearch - that is, create a new field that has that value you can then graph - it's a lot more efficient.

Elasticsearch aggregations don't calculate things **between** documents.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 6, 2018, 12:09am UTC](https://discuss.elastic.co/t/how-to-create-a-graph-from-sum-differences/118268/7 "2018-03-06T00:09:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
