# How to visualize the result of lucene query

**URL:** <https://discuss.elastic.co/t/how-to-visualize-the-result-of-lucene-query/183199>\
**Category:** Kibana\
**Created:** [May 28, 2019, 11:56pm UTC](https://discuss.elastic.co/t/how-to-visualize-the-result-of-lucene-query/183199 "2019-05-28T23:56:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JIYOUNG](https://avatars.discourse-cdn.com/v4/letter/j/3be4f8/32.png) [@JIYOUNG](https://discuss.elastic.co/u/JIYOUNG)\
**Post date:** [May 28, 2019, 11:56pm UTC](https://discuss.elastic.co/t/how-to-visualize-the-result-of-lucene-query/183199/1 "2019-05-28T23:56:49Z")

</div>

Hello, I am using Kibana 7.

Using lucene query, I can see the result of data in "Dev Tool" in Kibana.  
I want to visualize these result like "Data Table" or "Discovery" format.  
There are any way to do this?

1. Lucene Query  
GET hdb-thread\_qmx-2019.05\_idx/\_search  
{  
"query": {  
"range" : {  
"@timestamp" : {  
"gte" : "now-1h",  
"lte" : "now"  
}  
}  
},  
"size": 0,  
"aggs": {  
"group\_by\_query\_time": {  
"terms": {  
"field": "query\_time",  
"order": {  
"\_key": "desc"  
},  
"size": 1  
},  
"aggs": {  
"last\_query\_data": {  
"top\_hits": {  
"from": 0,  
"size": 100  
}  
}  
}  
}  
}  
}

2. The result  
{  
"took" : 32,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 1,  
"successful" : 1,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : {  
"value" : 10000,  
"relation" : "gte"  
},  
"max\_score" : null,  
"hits" :   
},  
"aggregations" : {  
"group\_by\_query\_time" : {  
"doc\_count\_error\_upper\_bound" : 0,  
"sum\_other\_doc\_count" : 317867,  
"buckets" : [  
{  
"key" : 1559087106569,  
"key\_as\_string" : "2019-05-28T23:45:06.569Z",  
"doc\_count" : 907,  
"last\_query\_data" : {  
"hits" : {  
"total" : {  
"value" : 907,  
"relation" : "eq"  
},  
"max\_score" : 1.0,  
"hits" : [  
{  
"\_index" : "hdb-thread\_qmx-2019.05\_idx",  
"\_type" : "\_doc",  
"\_id" : "sS7VAGsB9uC3kYuwefij",  
"\_score" : 1.0,  
"\_source" : {  
"thread\_type" : "Request",  
"application\_user\_name" : "",  
"sent\_message\_count" : null,  
"t5\_transaction\_id" : -1,  
"fetched\_record\_count" : null,  
"auto\_commit" : null,  
"lock\_owner\_transaction\_id" : null,  
"t4\_host" : null,  
"caller" : "qnrdpdb01:\*",  
"start\_time" : null,  
"connection\_type" : null,  
"port" : 30003,  
"idle\_time" : null,  
"duration" : 260909,  
"connection\_status" : null,  
"hierarchy" : "",  
"cpu\_time\_self" : 9751,  
"own" : null,  
"waiting\_schema\_name" : null,  
"lock\_wait\_component" : "Other",  
"received\_message\_count" : null,  
"user\_name" : "",  
"current\_operator\_name" : null,  
"blocked\_time" : null,  
"t4\_transaction\_id" : null,  
"application\_soruce" : "",  
"cpu\_time\_cumulative" : 9751,  
"waiting\_object\_name" : null,  
"client\_ip" : null,  
"t6\_transaction\_id" : null,  
"sent\_message\_size" : null,  
"host" : "qnrdpdb01",  
"received\_message\_size" : null,  
"t4\_port" : null,  
"lock\_wait\_name" : "",  
"lock\_type" : null,  
"last\_action" : null,  
"lock\_mode" : null,  
"t1\_transaction\_id" : null,  
"is\_history\_saved" : null,  
"application\_name" : "",  
"t3\_connection\_id" : null,  
"waiting\_object\_type" : null,  
"lock\_owner\_update\_transaction\_id" : null,  
"t1\_host" : null,  
"t1\_port" : null,  
"is\_encrypted" : null,  
"thread\_id" : 159378,  
"waiting\_record\_id" : null,  
"end\_time" : null,  
"service\_name" : "indexserver",  
"update\_transaction\_id" : -1,  
"created\_by" : null,  
"thread\_method" : "Queue Pull",  
"current\_statement\_id" : null,  
"blocked\_update\_transaction\_id" : null,  
"connection\_id" : -1,  
"creator\_thread\_id" : null,  
"thread\_detail" : "",  
"query\_time" : "2019-05-28T23:45:06.569Z",  
"t4\_connection\_id" : null,  
"@version" : "1",  
"statement\_hash" : null,  
"client\_host" : null,  
"thread\_state" : "Network Poll",  
"lock\_owner\_thread\_id" : 0,  
"client\_pid" : null,  
"blocked\_transaction\_id" : null,  
"t2\_transaction\_id" : null,  
"type" : "thread\_qmx",  
"memory\_size\_per\_connection" : null,  
"calling" : "qnrdpdb01:30002",  
"@timestamp" : "2019-05-28T23:45:18.514Z"  
}  
},

...

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [May 29, 2019, 2:54pm UTC](https://discuss.elastic.co/t/how-to-visualize-the-result-of-lucene-query/183199/2 "2019-05-29T14:54:06Z")

</div>

@JIYOUNG if you want to use the ES query syntax directly, this is only possible using [Vega](https://www.elastic.co/guide/en/kibana/current/vega-graph.html) but this will require knowledge of Vega and a fair amount of effort.

You can get close to what you're looking for using a Data Table Visualization similar to the following; however, you'll notice that we have to currently use the "Top Hit" aggregation with the "Metric" which only allows us to view one of the fields concatenated with a `,`, which may or may not be satisfactory:

 ![49%20AM](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a7d2c15148407f14e453bc4a3b79231591ab1af4.png)

---

<div class="post-metadata">

**Author:** ![JIYOUNG](https://avatars.discourse-cdn.com/v4/letter/j/3be4f8/32.png) [@JIYOUNG](https://discuss.elastic.co/u/JIYOUNG)\
**Post date:** [May 30, 2019, 4:17am UTC](https://discuss.elastic.co/t/how-to-visualize-the-result-of-lucene-query/183199/3 "2019-05-30T04:17:53Z")

</div>

Thanks for reply.

I already knew that "Top Hit" aggregation in Data Table. But I need to handle top hit data.  
(ex. sorting the result of "Top Hit" data)  
Then I have only one way to visualize ES query result using "Vega".

Do you have any sample of "Vega" using ES query syntax directly?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2019, 4:29am UTC](https://discuss.elastic.co/t/how-to-visualize-the-result-of-lucene-query/183199/4 "2019-06-27T04:29:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
