# How to create line visualization from log firewall automatically

**URL:** <https://discuss.elastic.co/t/how-to-create-line-visualization-from-log-firewall-automatically/100239>\
**Category:** Kibana\
**Created:** [September 12, 2017, 3:47pm UTC](https://discuss.elastic.co/t/how-to-create-line-visualization-from-log-firewall-automatically/100239 "2017-09-12T15:47:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![baharudin\_yusuf](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baharudin\_yusuf](https://discuss.elastic.co/u/baharudin_yusuf)\
**Post date:** [September 12, 2017, 3:47pm UTC](https://discuss.elastic.co/t/how-to-create-line-visualization-from-log-firewall-automatically/100239/1 "2017-09-12T15:47:23Z")

</div>

how to make line visualization of log firewall automatically with csv data format? I want to show the ip address is connected or disconnected at any time, suppose x is the clock and y is the ip address. of the many ip address it will be difficult when making visualization one by one ip address, how to automatically can not make visualization eg using phyton, coding etc. please know me if you know. thank you

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [September 12, 2017, 4:18pm UTC](https://discuss.elastic.co/t/how-to-create-line-visualization-from-log-firewall-automatically/100239/2 "2017-09-12T16:18:17Z")

</div>

Hey,

do you already have data in your Elasticsearch? What format does the documents have?  
I am also not sure exaclty what you want to draw in the chart. In the x-axis you want to have the time as far as I understood. On the y-axis should be the amount of online ip addresses?

It general you can do lots of charts also with Kibana directly (like splitting the chart by IP address via a Terms aggregation), but I would need some more information about your data format.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![baharudin\_yusuf](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baharudin\_yusuf](https://discuss.elastic.co/u/baharudin_yusuf)\
**Post date:** [September 12, 2017, 4:47pm UTC](https://discuss.elastic.co/t/how-to-create-line-visualization-from-log-firewall-automatically/100239/3 "2017-09-12T16:47:45Z")

</div>

i have data in my elasticsearch, format log is csv.  
sample log  
2017/06/07,10:45:21,TRAFFIC,end,91.247.xxx.xxx,103.220.xxx.xxx,Outside-to-Inside-service,,,web-browsing,80,tcp,allow,7334,6836,498,18,2017/06/07 10:43:47,educational-institutions,0,6470432598,UA,ID,from-policy  
sample visualization when i create

 ![Screenshot from 2017-09-12 23-25-13](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8c2d3121d124d5fd715092a669b82a3c8de7b38f.png)

the log is a lot of ip address, when I make the visualization one by one then I will have trouble. how to make the visualization as shown above automatically.thank

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [September 12, 2017, 5:11pm UTC](https://discuss.elastic.co/t/how-to-create-line-visualization-from-log-firewall-automatically/100239/4 "2017-09-12T17:11:41Z")

</div>

Hey,

if you need to create this saved search and charts for multiple IP adresses, you could indeed use a script for it.  
Kibana stores all it's data (i.e. also saved searches and visualizations) in an index called `.kibana` in your Elasticsearch cluster.

You can just query that index as any other and see what your saved search and chart object looks like and write a script (using Python, JS, or whatever you like) that creates those Elasticsearch documents for all IP adresses you need and inserts them into the `.kibana` index.

Cheers  
Tim

---

<div class="post-metadata">

**Author:** ![baharudin\_yusuf](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baharudin\_yusuf](https://discuss.elastic.co/u/baharudin_yusuf)\
**Post date:** [September 12, 2017, 5:22pm UTC](https://discuss.elastic.co/t/how-to-create-line-visualization-from-log-firewall-automatically/100239/5 "2017-09-12T17:22:00Z")

</div>

are there any examples or references that discuss it? if there is I may ask for references or url addresses that discuss it. I need a sample script to make it. thank

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [September 12, 2017, 5:25pm UTC](https://discuss.elastic.co/t/how-to-create-line-visualization-from-log-firewall-automatically/100239/6 "2017-09-12T17:25:03Z")

</div>

I guess there is no actual documentation on the format these documents are stored in there, so best would be, just to query the `.kibana` index (with the common regular Elasticsearch API) and look at the documents.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2017, 5:25pm UTC](https://discuss.elastic.co/t/how-to-create-line-visualization-from-log-firewall-automatically/100239/7 "2017-10-10T17:25:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
