# How to visualize sibling aggregations?

**URL:** <https://discuss.elastic.co/t/how-to-visualize-sibling-aggregations/211829>\
**Category:** Kibana\
**Created:** [December 13, 2019, 5:52pm UTC](https://discuss.elastic.co/t/how-to-visualize-sibling-aggregations/211829 "2019-12-13T17:52:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![anelson-edge](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anelson-edge/32/52865_2.png) [@anelson-edge](https://discuss.elastic.co/u/anelson-edge)\
**Post date:** [December 13, 2019, 5:52pm UTC](https://discuss.elastic.co/t/how-to-visualize-sibling-aggregations/211829/1 "2019-12-13T17:52:55Z")

</div>

insert sample data like this:

> <https://gist.github.com/anelson-vidscale/7a14fe5566974892aa39a9a2683084ae>

get the desired output using sibling aggregations like this:

> <https://gist.github.com/anelson-vidscale/4a8762e4a921f0431db68039343980fc>

sample firing alerts output:

> <https://gist.github.com/anelson-vidscale/ff3d0f4cbda15b41c3f1db3a49d2724b>

Now, how would I visualize that output?  
When I see non-trivial aggregations, I think time series visual builder.  
But notice that the output is not a time series.

Other than using Vega is there a way to visualize the output of my query inside Kibana?  
Or must I use something like Vega or Javascript to visualize my aggregations output?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [December 16, 2019, 10:01pm UTC](https://discuss.elastic.co/t/how-to-visualize-sibling-aggregations/211829/2 "2019-12-16T22:01:28Z")

</div>

@anelson-edge unfortunately the standard "data table" visualization doesn't support the bucket\_script aggregation and we're tracking support for this [here](https://github.com/elastic/kibana/issues/4707). If you can give this a +1, it'll help us prioritize it appropriately.

We can get most of the way there using a standard data-table visualization:

 ![Screen Shot 2019-12-16 at 1.56.26 PM](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff4c87ded28967092db58d8c6b4b7ec98e49e6d6.png)  
 ![Screen Shot 2019-12-16 at 1.59.24 PM](https://us1.discourse-cdn.com/elastic/original/3X/5/f/5f1dd7b49d2da31598ca776edaad183e92dbc1be.png) ![Screen Shot 2019-12-16 at 1.59.32 PM](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a101f47df6bc726740e458dfcbb6c2fa96af5adb.png)

Unfortunately, if you need a bucket-script aggregation and aren't using time series data, I don't know of a way outside of Vega to get you what you're looking for.

---

<div class="post-metadata">

**Author:** ![anelson-edge](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anelson-edge/32/52865_2.png) [@anelson-edge](https://discuss.elastic.co/u/anelson-edge)\
**Post date:** [December 18, 2019, 9:41pm UTC](https://discuss.elastic.co/t/how-to-visualize-sibling-aggregations/211829/3 "2019-12-18T21:41:30Z")

</div>

Well, the data is time series, but I only want the last event (based on the timestamp) for any given alert (alert-key).  
And then I only want those last events if the last event is in the firing state.  
I think it's a builtin assumption to "Time Series" Visual Builder that I have a time-series for the output (not just the input). 🙂

That said, I did learn a new trick from your "most of the way there" example.  
Thank you for responding.

I will learn some more Vega, but unfortunately there are known issues with the Kibana Vega integration (no scrollbars, no vega 5 support yet) that make Vega not quite perfect.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2020, 9:41pm UTC](https://discuss.elastic.co/t/how-to-visualize-sibling-aggregations/211829/4 "2020-01-15T21:41:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
