# How to set Split Lines when use nested json?

**URL:** <https://discuss.elastic.co/t/how-to-set-split-lines-when-use-nested-json/86955>\
**Category:** Kibana\
**Created:** [May 24, 2017, 11:27am UTC](https://discuss.elastic.co/t/how-to-set-split-lines-when-use-nested-json/86955 "2017-05-24T11:27:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tonghualin](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@tonghualin](https://discuss.elastic.co/u/tonghualin)\
**Post date:** [May 24, 2017, 11:27am UTC](https://discuss.elastic.co/t/how-to-set-split-lines-when-use-nested-json/86955/1 "2017-05-24T11:27:30Z")

</div>

hello all:

kibana version 5.3.0

I want to show chart like this:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7a10486cd12e7b493e837a486acb7b9763485963.png)

data format like this is ok.

{  
"\_index": "log20170524",  
"\_type": "sysinfo",  
"\_id": "AVw5TnPNslqZOjiWet\_p",  
"\_score": null,  
"\_source": {  
"info": [  
{  
"PercentSize": "22",  
"type": 1,  
"name": "cpu"  
}  
],  
"datetime": "1495610061000"  
},  
"sort": [  
1495610061000  
]  
}

{  
"\_index": "log20170524",  
"\_type": "sysinfo",  
"\_id": "AVw5TnPNslqZOjabet\_p",  
"\_score": null,  
"\_source": {  
"info": [  
{  
"PercentSize": "87",  
"type": 1,  
"name": "mem"  
}  
],  
"datetime": "1495610061000"  
},  
"sort": [  
1495610061000  
]  
}

but I change data to this:

{  
"\_index": "log20170524",  
"\_type": "sysinfo",  
"\_id": "AVw5TnPNslqUJjiWet\_p",  
"\_score": null,  
"\_source": {  
"info": [  
{  
"PercentSize": "87",  
"type": 1,  
"name": "mem"  
},  
{  
"PercentSize": "38",  
"type": 2,  
"name": "cpu"  
},  
{  
"PercentInode": "49",  
"PercentSize": "73",  
"type": 9,  
"name": "DiskTotal"  
},  
],  
"datetime": "1495610061000"  
},  
"sort": [  
1495610061000  
]  
}

the result chart:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b160ec2191db37e8389e83cf8a5756b40fa0871.png)

the right chart is all data average,not one.  
how to set ?

my setting:

![](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f8ecc4f4fd1ea86dda0c8ca922b73efe64bfc17e.png)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/1/6/16c77b5d9c3d562dc5dc7e429d0c52499e3746f0.png)

Thank you!

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [May 26, 2017, 4:06pm UTC](https://discuss.elastic.co/t/how-to-set-split-lines-when-use-nested-json/86955/2 "2017-05-26T16:06:37Z")

</div>

I'm not sure I understand your question, but here's a couple of points.

1. Kibana Visualizations always show aggregated data, not individual docs. If you zoom in to a small time range you might very well see individual doc values as the same as the aggregation. So if at one timestamp you only have one "cpu" value it doesn't matter if you choose "min", "max", "avg" etc because for a single value they're all the same.

2. It's much easier to read the docs you post if you format them are mark them as code like this;

data format like this is ok.

```auto
{
	"_index": "log20170524",
	"_type": "sysinfo",
	"id": "AVw5TnPNslqZOjiWetp",
	"_score": null,
	"_source": {
		"info": [{
			"PercentSize": "22",
			"type": 1,
			"name": "cpu"
		}],
		"datetime": "1495610061000"
	},
	"sort": [1495610061000]
}
{
	"_index": "log20170524",
	"_type": "sysinfo",
	"id": "AVw5TnPNslqZOjabetp",
	"_score": null,
	"_source": {
		"info": [{
			"PercentSize": "87",
			"type": 1,
			"name": "mem"
		}],
		"datetime": "1495610061000"
	},
	"sort": [1495610061000]
}

```

but I change data to this:

```auto
{
	"_index": "log20170524",
	"_type": "sysinfo",
	"id": "AVw5TnPNslqUJjiWetp",
	"_score": null,
	"_source": {
		"info": [{
			"PercentSize": "87",
			"type": 1,
			"name": "mem"
		},
		{
			"PercentSize": "38",
			"type": 2,
			"name": "cpu"
		},
		{
			"PercentInode": "49",
			"PercentSize": "73",
			"type": 9,
			"name": "DiskTotal"
		},
		],
		"datetime": "1495610061000"
	},
	"sort": [1495610061000]
}

```

1. It sounds like your first chart was created from the data where each metric was it's own doc in Elasticsearch and looks like you want. Why did you change to have multiple metrics in each doc?

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![tonghualin](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@tonghualin](https://discuss.elastic.co/u/tonghualin)\
**Post date:** [May 27, 2017, 2:34am UTC](https://discuss.elastic.co/t/how-to-set-split-lines-when-use-nested-json/86955/3 "2017-05-27T02:34:32Z")

</div>

Thank for your reply.

1. the data is inserted at the same time. used to show the status of server machine. so the datetime or other information(like ip, mac) is same. use nested struction can save storage space, only need insert one record once. otherwise i need insert three records once.

2. my problem is "i want to show cpu, memory, disk separately, the value of them are diffrent, but strange thing is the aggregation value of them are the same, it's wrong"

forgive me for my poor English

Regards,  
Tonghualin

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [May 30, 2017, 6:36pm UTC](https://discuss.elastic.co/t/how-to-set-split-lines-when-use-nested-json/86955/4 "2017-05-30T18:36:51Z")

</div>

Did you mix the data from your first format and your second format in the same index? Or did you wipe the index out and load the data the second way?

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [May 30, 2017, 8:32pm UTC](https://discuss.elastic.co/t/how-to-set-split-lines-when-use-nested-json/86955/5 "2017-05-30T20:32:41Z")

</div>

Here's a suggestion for a different format that works for charting. In this test data I created I just concatenated the 3 `name` fields with the `PercentSize` values;

```auto
post /discuss3/test
{
  "memPercentSize": 87,
  "cpuPercentSize": 38,
  "diskPercentSize": 73,
  "datetime": "2017-05-30T00:00:00"
}
post /discuss3/test
{
  "memPercentSize": 97,
  "cpuPercentSize": 48,
  "diskPercentSize": 83,
  "datetime": "2017-05-30T00:01:00"
}
post /discuss3/test
{
  "memPercentSize": 47,
  "cpuPercentSize": 18,
  "diskPercentSize": 23,
  "datetime": "2017-05-30T00:02:00"
}
post /discuss3/test
{
  "memPercentSize": 57,
  "cpuPercentSize": 58,
  "diskPercentSize": 53,
  "datetime": "2017-05-30T00:03:00"
}

```

Now I can add each of those to a line chart like this;

 ![](https://us1.discourse-cdn.com/elastic/original/3X/4/8/4899a94f2c5aeab4e930e2d29571e32d2baefb41.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2017, 8:32pm UTC](https://discuss.elastic.co/t/how-to-set-split-lines-when-use-nested-json/86955/6 "2017-06-27T20:32:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
