# How to visualize network bandwidth

**URL:** <https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293>\
**Category:** Kibana\
**Created:** [August 29, 2015, 9:59pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293 "2015-08-29T21:59:13Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Keven\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keven_wang/32/4476_2.png) [@Keven\_Wang](https://discuss.elastic.co/u/Keven_Wang)\
**Post date:** [August 29, 2015, 9:59pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/1 "2015-08-29T21:59:13Z")

</div>

Hi all,

I am using collectd and logstash to push network interface statistics to elastic search and want to visualize actual network bandwidth. The problem is the data sent to elastic search is cumulative data, like total received/sent packets (rx and tx) on the network interface. I wonder how i can de-cumalative the data? The easiest way would be get the diff of the value between two event and divide by the time difference between two log entries.  
For example: log entry 1 happens at time t1 with tx1 and rx1. log entry 2 happens at time t2, with tx2, rx2. So the uplink speed would be (tx2-tx1)/(t2-t1). I wonder i i can visualize the uplink speed over time?  
Thank you all very much!

BR/Keven

---

<div class="post-metadata">

**Author:** ![Pieter\_Agenbag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pieter_agenbag/32/4562_2.png) [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Post date:** [August 31, 2015, 1:51pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/2 "2015-08-31T13:51:59Z")

</div>

As far as I know , thats not possible.  
You'll have to calculate the differences when loading the data... Thats unfortunately not where your problems end, because I suspect you'll then end up with number of bytes sent for time period and not a bitrate (as bandwidth is usually described)

Kibana makes things even more difficult because it will/can automatically scale the interval of the graphs, to accommodate small to very large datasets.

If you're happy plotting the "sum of bytes" , then you're gold if you can precalculate the differences . If you know there will always be an entry for every interface for every timeperiod - then you can probably get away with calculating bitrates and plotting average of that.

I ended up having to to code some custom stuff into the kibana backend to plot my bandwidth graphs.

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [December 9, 2015, 5:47am UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/3 "2015-12-09T05:47:20Z")

</div>

Btw, Timelion plugin for Kibana was just released, which makes doing this type of math on time series trivial: [https://www.elastic.co/blog/timelion-timeline](https://www.elastic.co/blog/timelion-timeline)

---

<div class="post-metadata">

**Author:** ![erikstephens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erikstephens/32/5430_2.png) [@erikstephens](https://discuss.elastic.co/u/erikstephens)\
**Post date:** [December 9, 2015, 7:00pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/4 "2015-12-09T19:00:39Z")

</div>

@Keven_Wang, I think you want the [derivative elasticsearch aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-derivative-aggregation.html) but [not supported by kibana yet](https://github.com/elastic/kibana/issues/1743).

@tbragin, can you or the team share any rough estimates or milestones about when counter metrics will be supported? Is the plan to be able to include timelion graphs as visualizations in kibana dashboards?

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [May 11, 2016, 2:44pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/5 "2016-05-11T14:44:18Z")

</div>

Trying to get into timelion specifically to test derivative aggregation, only I seem to have an issue validating my timelion config in the tuturial, what fora would be right to dicuss timelion, here in Kibana I assume?

Appreciate any good timelion doc pointers!

TIA

---

<div class="post-metadata">

**Author:** ![pereyrdi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pereyrdi/32/12480_2.png) [@pereyrdi](https://discuss.elastic.co/u/pereyrdi)\
**Post date:** [October 13, 2016, 12:57pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/6 "2016-10-13T12:57:12Z")

</div>

Hi Keven! Im with same problem, Im sending bandwith snmp information to elasticsearch, but is the cumulative data, from ifHCInOctets and ifHCOutOctets oids. Did you solved it ?  
Diego

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [October 15, 2016, 11:27pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/7 "2016-10-15T23:27:24Z")

</div>

I went for derivative aggregation in [grafana](http://grafana.org) on top of our ES cluster, also find it's metric dashboards nice(r) 🙂

---

<div class="post-metadata">

**Author:** ![pereyrdi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pereyrdi/32/12480_2.png) [@pereyrdi](https://discuss.elastic.co/u/pereyrdi)\
**Post date:** [October 17, 2016, 3:39pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/8 "2016-10-17T15:39:09Z")

</div>

Thanks, Im trying to do it, but I dont understend how.  
something like this ?

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a29dad7324603abd14d04f77948f4283d079a3a2.png)

I send the snmp info collected to logstash and then to elastic.

Thanks !  
Diego P.

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [October 17, 2016, 7:15pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/9 "2016-10-17T19:15:43Z")

</div>

[CleverTap](https://blog.clevertap.com/telemetry-with-collectd-logstash-elasticsearch-and-grafana-elg/)  
might also help you to understand howto use [ES derivate aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-derivative-aggregation.html) You need a parent metric/aggregation (not disaplyed) onto which you can make the derivate metric.

Not sure if I needed to enable inline scripts in my ES cluster with this in elasticsearch.yml:

script.inline: true

or it was for some other feature this was needed.

---

<div class="post-metadata">

**Author:** ![pereyrdi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pereyrdi/32/12480_2.png) [@pereyrdi](https://discuss.elastic.co/u/pereyrdi)\
**Post date:** [October 18, 2016, 3:23pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/10 "2016-10-18T15:23:24Z")

</div>

Thanks, I must read and study more about that, but I test this code with sense and get what i need, now i have to solve how graph it with kibana and json imput.

> {  
> "aggs": {  
> "1": {  
> "date\_histogram": {  
> "field": "@timestamp",  
> "interval": "5m"  
> },  
> "aggs": {  
> "rx\_avg": {  
> "avg": {  
> "field": "rx"  
> }  
> },  
> "rx\_deriv": {  
> "derivative": {  
> "buckets\_path": "rx\_avg"  
> } } } } } }

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [October 18, 2016, 3:39pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/11 "2016-10-18T15:39:56Z")

</div>

Yes if you prefer Kibana for this, I thought that you, like I graphed, with grafana as your SD seems to show and as CleverTab can guide you to. Can't help on Kibana with this 🙂

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [October 18, 2016, 4:21pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/12 "2016-10-18T16:21:03Z")

</div>

Maybe Kibana wouldn't just yet, add your voice to [this issue](https://github.com/elastic/kibana/issues/4584)

Also see this [ES blog post](https://www.elastic.co/blog/staying-in-control-with-moving-averages-part-1)

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [October 18, 2016, 4:28pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/13 "2016-10-18T16:28:02Z")

</div>

Sample of how one of my collectd counter metrics sampled every 300 sec is graphed in Grafana +2.6 through an ES derivate aggregation , again belive you need to enable inline scripting in your ES cluster for this to work

 ![](https://us1.discourse-cdn.com/elastic/original/2X/9/9f159f3ae0e8eca8009549638ec6c3b4f00ceb12.png)

---

<div class="post-metadata">

**Author:** ![pereyrdi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pereyrdi/32/12480_2.png) [@pereyrdi](https://discuss.elastic.co/u/pereyrdi)\
**Post date:** [October 18, 2016, 7:35pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/14 "2016-10-18T19:35:14Z")

</div>

Great Steffen !  
I make it work.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/d9604d2349e2396b13eba53a34e7cec9b38a09b7.png)

Thanks a lot !

I dont know why if i zoom more than last 24hs the graph show up and dissapear. We will see about next time.  
Thanks again  
diego

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [October 18, 2016, 8:42pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/15 "2016-10-18T20:42:04Z")

</div>

Good, remember you'll have to divide your metric with your sampling interval to get per-sec or per-minute whatever you want (\_value/300 for our 5 min interval gives us per-sec values) and then you may want set proper Y-axe Unit under Axes tab to other than 'short' to display it nicely 🙂

I've also seen some issues with not-showing graphs initially, but then I do something that'll make the panel refresh. alter a template var, change time zoom a bit... believe it's another issue in Grafana, maybe connected with use of the ES pipeline aggregation, dunno. But at least you have a chance to see derivates instead of counters.

HInt: If you want to trunk of counter reset, which'll give large 'negative' spikes, limit the Y axe value to zero.

---

<div class="post-metadata">

**Author:** ![MikeC](https://avatars.discourse-cdn.com/v4/letter/m/977dab/32.png) [@MikeC](https://discuss.elastic.co/u/MikeC)\
**Post date:** [December 2, 2016, 11:34am UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/16 "2016-12-02T11:34:01Z")

</div>

could you share your solution code-wise ?

---

<div class="post-metadata">

**Author:** ![pereyrdi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pereyrdi/32/12480_2.png) [@pereyrdi](https://discuss.elastic.co/u/pereyrdi)\
**Post date:** [December 2, 2016, 2:19pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/17 "2016-12-02T14:19:46Z")

</div>

Hi, in the screenshot u can see what I did. The query.  
Diego

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:33pm UTC](https://discuss.elastic.co/t/how-to-visualize-network-bandwidth/28293/18 "2017-07-06T13:33:52Z")

</div>


