# How to graph this?

**URL:** <https://discuss.elastic.co/t/how-to-graph-this/85927>\
**Category:** Kibana\
**Created:** [May 16, 2017, 12:23pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927 "2017-05-16T12:23:37Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![imaad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imaad/32/48628_2.png) [@imaad](https://discuss.elastic.co/u/imaad)\
**Post date:** [May 16, 2017, 12:23pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/1 "2017-05-16T12:23:38Z")

</div>

Hello,

I need to graph the top 10 URI response over time with duration \> 5s.

I managed to graph the top 10 URI reponse over time but I don't know how to add **the condition duration \>5s**.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff6275b6ed788e6adaf59508d64210ef9eae3375.png)

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 16, 2017, 12:48pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/2 "2017-05-16T12:48:14Z")

</div>

I am absolutely not sure about this, but try on your bucket to click on advanced and try as JSON input:

```auto
{"script": "if (doc['your_duration'].value > 5) {_value} else {0} "}

```

This works quite fine on a sum aggregation, but on a term/count, I'm not sure

Anyway, It will propably not work well (I'm just beggining to undertand how this input works), but try investigating on JSON input until someone replies correctly to you

---

<div class="post-metadata">

**Author:** ![imaad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imaad/32/48628_2.png) [@imaad](https://discuss.elastic.co/u/imaad)\
**Post date:** [May 16, 2017, 1:13pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/3 "2017-05-16T13:13:41Z")

</div>

> [@Nico-DF](#):
>
> {"script": "if (doc['your\_duration'].value \> 5) {\_value} else {0} "}

Thank you, it's a good idea. I tried but I get this error :  
`{"type":"index_out_of_bounds_exception","reason":"index_out_of_bounds_exception: null"}}},"status":500}`

---

<div class="post-metadata">

**Author:** ![imaad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imaad/32/48628_2.png) [@imaad](https://discuss.elastic.co/u/imaad)\
**Post date:** [May 16, 2017, 2:08pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/4 "2017-05-16T14:08:26Z")

</div>

Do someone have another suggestion?  
Thank you

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 16, 2017, 2:18pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/5 "2017-05-16T14:18:33Z")

</div>

Not really.

I might have a fix, but it's truly horrible.  
In logstash, made these logs have a field like: `count_response` and set it to 1 (integer).

Then, on your y-axis, use sum on this new field instead of count, and on y-axis again, use the JSON input:

```auto
{"script": "if (doc['your_duration'].value > 5) {1} else {0}"}

```

It will work I think. But it's kinda clunky. Use it as a temporary fix if you want, but keep searching for a better way to achieve this

(btw, got same error as you if I try this on my bucket and not on my metric (y-axis))

---

<div class="post-metadata">

**Author:** ![imaad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imaad/32/48628_2.png) [@imaad](https://discuss.elastic.co/u/imaad)\
**Post date:** [May 17, 2017, 9:07am UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/6 "2017-05-17T09:07:18Z")

</div>

Ok Thank you Nico.

I'm trying to find a solution without logstash....

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 17, 2017, 9:09am UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/7 "2017-05-17T09:09:34Z")

</div>

Oh wait a minute...  
Did you try, instead of linking the graph to your index, to link it to a kibana search?

---

<div class="post-metadata">

**Author:** ![imaad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imaad/32/48628_2.png) [@imaad](https://discuss.elastic.co/u/imaad)\
**Post date:** [May 17, 2017, 9:18am UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/8 "2017-05-17T09:18:07Z")

</div>

No, I didn't try and I don't know how to do it

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 17, 2017, 9:22am UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/9 "2017-05-17T09:22:30Z")

</div>

Ok then.

Go to discover, on search bar, type: (supposing 'duration' is the field you want to test and is type Number):

Type: duration:\>=5 (or 5000 if in ms, etc.)

Normally, on discover, you shall now only have the fields you want to display (maybe add conditions to you search if there is other logs).  
Now save it (top right corner).

Then, go to visualization, select vertical bar chart, and now, instead of choosing your index as your source, choose your new saved search. And done.

For further info on how queries works with Kibana/ES:

> **[Elasticsearch/Kibana Queries - In Depth Tutorial](https://www.timroes.de/2016/05/29/elasticsearch-kibana-queries-in-depth-tutorial/#using-json-in-the-kibana-search)**
>
> This tutorial explains how to write and understand Kibana and Elasticsearch queries
> in depth and how the mapping of Elastichsearch influences these queries.

---

<div class="post-metadata">

**Author:** ![imaad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imaad/32/48628_2.png) [@imaad](https://discuss.elastic.co/u/imaad)\
**Post date:** [May 17, 2017, 12:38pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/10 "2017-05-17T12:38:38Z")

</div>

Yes, I see what you mean but with this method I'll just display the duration:\>5. However, I need top 10 URI response over time with duration \> 5s.....

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 17, 2017, 12:43pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/11 "2017-05-17T12:43:41Z")

</div>

You mean that you want the top 10 URI (independant of their duration) and then only display those with duration \> 5s?

---

<div class="post-metadata">

**Author:** ![imaad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imaad/32/48628_2.png) [@imaad](https://discuss.elastic.co/u/imaad)\
**Post date:** [May 17, 2017, 12:45pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/12 "2017-05-17T12:45:32Z")

</div>

I need the top 10 URI dependant on their duration (duration :\>5s) 🙂

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 17, 2017, 12:46pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/13 "2017-05-17T12:46:31Z")

</div>

then how the search filter won't work?  
It is only a filter, you get all the document (that means all their fields) that match the condition provided

You just use these as a source data, then your graph will be the same (config-wise) as your 1st one

---

<div class="post-metadata">

**Author:** ![imaad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imaad/32/48628_2.png) [@imaad](https://discuss.elastic.co/u/imaad)\
**Post date:** [May 17, 2017, 12:53pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/14 "2017-05-17T12:53:52Z")

</div>

Yes I already tried a filter : duration:[0 TO \*] . I tested with duration equal to 0s to find all documents where number is greater or equal to 0. But nothing was displayed.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/0/20898439ca50f97f503329b7b60ffd35cb9935f7.png)

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 17, 2017, 1:07pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/15 "2017-05-17T13:07:44Z")

</div>

Was not the intended place to write the filter... I recap again

**Go to Discover tab**.

On **Search Bar** , type: `name_of_your_duration_field:>=5`if the field is in second

Still on discover page, click on save, choose a name and save.

**Go to Visualize tab**

Create a **new Vertical Bar chart vizualisation**

Now, instead of logstash-\* (I presume) as a source, choose your freshly saved search.

Now, re-setup your graph (like in your 1st post) and it shall be ok.

---

<div class="post-metadata">

**Author:** ![imaad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imaad/32/48628_2.png) [@imaad](https://discuss.elastic.co/u/imaad)\
**Post date:** [May 17, 2017, 1:19pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/16 "2017-05-17T13:19:20Z")

</div>

I understand what you said before but my Elasticsearch is customized as a TSDB so my field duration is not indexed so she is not searchable.

I get nothing when I type duration:\>5 on the search Bar that's why i was looking for a different way.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2017, 1:19pm UTC](https://discuss.elastic.co/t/how-to-graph-this/85927/17 "2017-06-14T13:19:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
