# How to sum all numeric values of a particular field

**URL:** <https://discuss.elastic.co/t/how-to-sum-all-numeric-values-of-a-particular-field/215838>\
**Category:** Kibana\
**Created:** [January 21, 2020, 8:40am UTC](https://discuss.elastic.co/t/how-to-sum-all-numeric-values-of-a-particular-field/215838 "2020-01-21T08:40:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kashif](https://avatars.discourse-cdn.com/v4/letter/k/ecc23a/32.png) [@Kashif](https://discuss.elastic.co/u/Kashif)\
**Post date:** [January 21, 2020, 8:40am UTC](https://discuss.elastic.co/t/how-to-sum-all-numeric-values-of-a-particular-field/215838/1 "2020-01-21T08:40:43Z")

</div>

Hi,  
I configured the AWS Appstream log in ELK ( 7.5.1 )  
I want to make visualization of two filed.  
user\_id and session\_duration\_in\_seconds

fields example

user\_id kashif  
session\_duration\_in\_seconds 300

How can I make a visualization that it will show the the sum of all values ( session\_duration\_in\_seconds ) for that user according to selected time.

---

<div class="post-metadata">

**Author:** ![Elvis\_Saravia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elvis_saravia/32/45624_2.png) [@Elvis\_Saravia](https://discuss.elastic.co/u/Elvis_Saravia)\
**Post date:** [January 21, 2020, 10:49am UTC](https://discuss.elastic.co/t/how-to-sum-all-numeric-values-of-a-particular-field/215838/2 "2020-01-21T10:49:14Z")

</div>

Hi Kashif, thanks for taking the time to post your question here.

I tried to create a sample index with those same fields and added some sample data. If I understood your problem correctly, you can do the following to get the visualization you need.

- You create a 'Vertical Bar' visualization
- Then for the **Metric** , you select **Sum** as the aggregation and it will ask you to select a field, which in your case will be `session_duration_in_seconds`.
- You create buckets according to your `date` field and specify the time interval.
- Once you have done this, you get buckets (vertical bars) that represent the summation of the `session_duration_in_seconds` for all users across time.
- Since you want the analysis to be for a specific user, you create a **filter** at the top (below the search bar) and select `user_id:<your user>`.
- Now the analysis should only be performed for that particular user.
- To select the desired timeframe just use the time filter at the top right.

Hopefully, it helps, and below is a snapshot of how I rendered the visualization. Let me know if this is what you were looking for? Otherwise, we can discuss more of the issue at hand. Thanks!

 ![Screenshot 2020-01-21 at 11.45.45](https://us1.discourse-cdn.com/elastic/original/3X/4/2/425cb5ff55eaee1a28d5dbcffd613fdd2f9f732b.png)

---

<div class="post-metadata">

**Author:** ![Kashif](https://avatars.discourse-cdn.com/v4/letter/k/ecc23a/32.png) [@Kashif](https://discuss.elastic.co/u/Kashif)\
**Post date:** [January 22, 2020, 6:04am UTC](https://discuss.elastic.co/t/how-to-sum-all-numeric-values-of-a-particular-field/215838/3 "2020-01-22T06:04:43Z")

</div>

Hi Elvis,  
Thanks for your reply. I was trying to use sum as aggregation but its gives me error message something that I dont have sum field data etc.

Then someone pointed out that I need to change the session\_duration\_in\_seconds field from string to float.

I did below in filter.  
mutate{  
convert =\> {  
"session\_duration\_in\_seconds" =\> "float"  
}  
}

After that I am able to get the sum of the session\_duration\_in\_seconds.

---

<div class="post-metadata">

**Author:** ![Kashif](https://avatars.discourse-cdn.com/v4/letter/k/ecc23a/32.png) [@Kashif](https://discuss.elastic.co/u/Kashif)\
**Post date:** [January 22, 2020, 6:10am UTC](https://discuss.elastic.co/t/how-to-sum-all-numeric-values-of-a-particular-field/215838/4 "2020-01-22T06:10:54Z")

</div>

I want to ask one thing.  
I am getting my required result like below

User Session\_duration\_in\_seconds  
kashif 300  
user2 500  
user3 450  
user4 7000

is it possible that I can display ( in Data Table ) time in minutes or hours etc. original value which is receiving in logs is in seconds.

---

<div class="post-metadata">

**Author:** ![Elvis\_Saravia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elvis_saravia/32/45624_2.png) [@Elvis\_Saravia](https://discuss.elastic.co/u/Elvis_Saravia)\
**Post date:** [January 23, 2020, 3:22pm UTC](https://discuss.elastic.co/t/how-to-sum-all-numeric-values-of-a-particular-field/215838/5 "2020-01-23T15:22:09Z")

</div>

Hi Kashif,

If you just want to display those values in minutes or hours, you can try using a scripted field.

Go into Management and select the index pattern you are working with and then create a scripted field. Then give it a name and use something like below:

for minutes:  
`doc['session_duration_in_seconds'].value / 60`

OR

for hours:  
`doc['session_duration_in_seconds'].value / 3600`

You can create both of them as separate scripted fields so you have access to both of them in the Data Table visualization.

When you are in the Table visualization, select a new Metric (could be Max) and pick the newly created scripted field.

Here is a bit more on scripted fields: [https://www.elastic.co/guide/en/kibana/current/scripted-fields.html](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2020, 3:32pm UTC](https://discuss.elastic.co/t/how-to-sum-all-numeric-values-of-a-particular-field/215838/6 "2020-02-20T15:32:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
