# How to put a visualization directly in Kibana/ElasticSearch?

**URL:** <https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325>\
**Category:** Kibana\
**Created:** [April 25, 2016, 1:40pm UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325 "2016-04-25T13:40:35Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![TonyPoiSpinner](https://avatars.discourse-cdn.com/v4/letter/t/5f8ce5/32.png) [@TonyPoiSpinner](https://discuss.elastic.co/u/TonyPoiSpinner)\
**Post date:** [April 25, 2016, 1:40pm UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/1 "2016-04-25T13:40:35Z")

</div>

Hello everyone,

I tried something and I think it's worth sharing 🙂

I'm trying to write a script to automatically create a new dashboard according to a specific user (for that, it is the search that changes).

More precisely, as a dashboard is made of visualizations, we need to create the visualizations in the first place. I was blocked at this step, creating the visualization directly via a CURL -XPOST request to ElasticSearch.

Because in order to do the final dashboard, we need to :

1. Write the search(es)
2. Create the visualization(s)
3. Create the dashboard made of visualizations

Schematically :

Input : Username --\> Myscript --\> Dashboard of the user

To make things clear, a visualization is only a JSON document in the path (in my case, but surely in yours too) :  
'[http://localhost:9200/.kibana/visualization/\*](http://localhost:9200/.kibana/visualization/*)'  
In ElasticSearch, and Kibana reads it to display it.

So it's simple, add a new visualization as you add a new document through the ElasticSearch API.  
To do that, and to know what the visualization you want to create looks like, you can create it using Kibana web interface; and once you validate and it's added in ElasticSearch, you see the ElasticSearch document.

Let's say we created a Pie Chart using Kibana named "Test1" : we request it in ElasticSearch to see the document.

```auto
curl -XGET 'http://localhost:9200/.kibana/visualization/Test1'

```

You should have this kind of result :

```auto
 {
   "_index":".kibana",
   "_type":"visualization",
   "_id":"Test1",
   "_version":1,
   "found":true,
   "_source":{
      "title":"Test1",
      "visState":"{\"aggs\":[{\"id\":\"1\",\"params\":{},\"schema\":\"metric\",\"type\":\"count\"},{\"id\":\"2\",\"params\":{\"field\":\"type.raw\",\"order\":\"desc\",\"orderBy\":\"1\",\"size\":10},\"schema\":\"segment\",\"type\":\"terms\"}],\"listeners\":{},\"params\":{\"addLegend\":true,\"addTooltip\":true,\"isDonut\":false,\"shareYAxis\":true},\"title\":\"New Visualization\",\"type\":\"pie\"}",
      "uiStateJSON":"{}",
      "description":"",
      "version":1,
      "kibanaSavedObjectMeta":{
         "searchSourceJSON":"{\"index\":\"logstash-*\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"YOUR KIBANA DISCOVER SEARCH HERE\"}},\"filter\":[]}"
      }
   }
}

```

So, then, we want to create a similar document into ElasticSearch directly, without using Kibana, as we would need it in a script. The query looks like this :

```auto
curl -XPOST 'http://localhost:9200/.kibana/visualization/Test2' -d '
{"title":"Test2","visState":"{\"aggs\":[{\"id\":\"1\",\"params\":{},\"schema\":\"metric\",\"type\":\"count\"},{\"id\":\"2\",\"params\":{\"field\":\"type.raw\",\"order\":\"desc\",\"orderBy\":\"1\",\"size\":10},\"schema\":\"segment\",\"type\":\"terms\"}],\"listeners\":{},\"params\":{\"addLegend\":true,\"addTooltip\":true,\"isDonut\":false,\"shareYAxis\":true},\"title\":\"New Visualization\",\"type\":\"pie\"}","uiStateJSON":"{}","description":"","version":1,"kibanaSavedObjectMeta":{"searchSourceJSON":"{\"index\":\"logstash-*\",\"query\":{\"query_string\":{\"analyze_wildcard\":true,\"query\":\"YOUR KIBANA DISCOVER SEARCH HERE\"}},\"filter\":[]}"}}
'

```

Note that we used the Source part of the first query to make the POST.

That's it ! You can check the Pie Chart has been well created in Kibana 😉

Have a good day, I hope this has been useful.

Tony

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 26, 2016, 10:29am UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/2 "2016-04-26T10:29:21Z")

</div>

Thanks for sharing! I reformatted a bit your post so I hope it's even easier to read and reuse as a recipe.

---

<div class="post-metadata">

**Author:** ![abhi.kedari](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@abhi.kedari](https://discuss.elastic.co/u/abhi.kedari)\
**Post date:** [June 8, 2016, 11:39pm UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/3 "2016-06-08T23:39:20Z")

</div>

SoI think .kibana index is available only in version 4.1 or greater.  
What about version 4.0.\* or earlier?

---

<div class="post-metadata">

**Author:** ![TonyPoiSpinner](https://avatars.discourse-cdn.com/v4/letter/t/5f8ce5/32.png) [@TonyPoiSpinner](https://discuss.elastic.co/u/TonyPoiSpinner)\
**Post date:** [July 7, 2016, 9:17am UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/4 "2016-07-07T09:17:10Z")

</div>

I don't know I didn't test it and I'm not using an old version, but you can 🙂

---

<div class="post-metadata">

**Author:** ![murban](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@murban](https://discuss.elastic.co/u/murban)\
**Post date:** [August 29, 2016, 8:26pm UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/5 "2016-08-29T20:26:19Z")

</div>

Hi!

I was trying to create the visualization directly, and I ended up with the same json object as you (templating in my own parameters where needed) The server returns 200, saying that the visualization is created, but it does not show up in the visualization list. Any clue why this might happen?

Response:  
{"\_index":".kibana","\_type":"vizualization","\_id":"test\_viz4","\_version":1,"\_shards":{"total":2,"successful":1,"failed":0},"created":true}

A bit more information: I'm using kibana 4.4.2

---

<div class="post-metadata">

**Author:** ![pdoyle](https://avatars.discourse-cdn.com/v4/letter/p/f19dbf/32.png) [@pdoyle](https://discuss.elastic.co/u/pdoyle)\
**Post date:** [December 6, 2016, 7:34pm UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/6 "2016-12-06T19:34:09Z")

</div>

The .kibana index takes visState which is a json string within a json object. The json string needs quote escaping and everything. Here is how to make a simple pie chart using term aggregation:  
( note "New Visualzation". In 4.4.2 this is just a place holder it appears and MyTitle is what is important. )

`curl -XPOST 'http://myserver:9200/.kibana/visualization' -d '{"title": "MyTitle", "visState": "{\"title\":\"New Visualization\",\"type\":\"pie\",\"params\":{\"shareYAxis\":true,\"addTooltip\":true,\"addLegend\":true,\"isDonut\":false},\"aggs\":[{\"id\":\"1\",\"type\":\"count\",\"schema\":\"metric\",\"params\":{}},{\"id\":\"2\",\"type\":\"terms\",\"schema\":\"segment\",\"params\":{\"field\":\"MyAggField\",\"size\":5,\"order\":\"desc\",\"orderBy\":\"1\"}}],\"listeners\":{}}", "uiStateJSON": "{}", "description": "", "savedSearchId": "MySavedSearch", "version": 1, "kibanaSavedObjectMeta": { "searchSourceJSON": "{\"filter\":[]}"}}'`

---

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [April 11, 2017, 7:58pm UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/7 "2017-04-11T19:58:14Z")

</div>

Exactly what I was looking for, but is there any suggestion on how to write a search?

---

<div class="post-metadata">

**Author:** ![TonyPoiSpinner](https://avatars.discourse-cdn.com/v4/letter/t/5f8ce5/32.png) [@TonyPoiSpinner](https://discuss.elastic.co/u/TonyPoiSpinner)\
**Post date:** [April 11, 2017, 8:28pm UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/8 "2017-04-11T20:28:21Z")

</div>

Hi Peter,  
I'm no more into elastic nowadays but by memory I'd say to look at the request through your web-browser analyzer ?  
I would have done it like this imo  
Good luck  
Tony

ps: my bad, forget what I wrote.  
If you look attentively on my original post :  
I wrote in the 2nd quote :  
{  
"\_index":".kibana",  
"\_type":"visualization",  
"\_id":"Test1",  
"\_version":1,  
"found":true,  
"\_source":{  
"title":"Test1",  
"visState":"{"aggs":[{"id":"1","params":{},"schema":"metric","type":"count"},{"id":"2","params":{"field":"type.raw","order":"desc","orderBy":"1","size":10},"schema":"segment","type":"terms"}],"listeners":{},"params":{"addLegend":true,"addTooltip":true,"isDonut":false,"shareYAxis":true},"title":"New Visualization","type":"pie"}",  
"uiStateJSON":"{}",  
"description":"",  
"version":1,  
"kibanaSavedObjectMeta":{  
"searchSourceJSON":"{"index":"logstash-\*","query":{"query\_string":{"analyze\_wildcard":true,"query":" **YOUR KIBANA DISCOVER SEARCH HERE**"}},"filter":[]}"  
}  
}  
}  
Does it answer your question ?

---

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [April 11, 2017, 8:59pm UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/9 "2017-04-11T20:59:05Z")

</div>

Thank you for the info. This only answers how to create a visualization but does not give me an idea on how to create a saved search for the visualization to be used.

---

<div class="post-metadata">

**Author:** ![matti](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@matti](https://discuss.elastic.co/u/matti)\
**Post date:** [May 16, 2017, 10:55am UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/10 "2017-05-16T10:55:28Z")

</div>

Use the content of the `_source` keyword you get from exporting a saved search and POST it to e.g. `http://myserver:9200/.kibana/search` or PUT it to e.g. `http://myserver:9200/.kibana/search/ddddddd-dddd-dddd-dddd-dddddddd/_create`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:31pm UTC](https://discuss.elastic.co/t/how-to-put-a-visualization-directly-in-kibana-elasticsearch/48325/11 "2017-07-06T13:31:45Z")

</div>


