# Is it possible to dynamically aggregate time?

**URL:** <https://discuss.elastic.co/t/is-it-possible-to-dynamically-aggregate-time/41767>\
**Category:** Kibana\
**Created:** [February 15, 2016, 11:18am UTC](https://discuss.elastic.co/t/is-it-possible-to-dynamically-aggregate-time/41767 "2016-02-15T11:18:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sauha](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@Sauha](https://discuss.elastic.co/u/Sauha)\
**Post date:** [February 15, 2016, 11:18am UTC](https://discuss.elastic.co/t/is-it-possible-to-dynamically-aggregate-time/41767/1 "2016-02-15T11:18:37Z")

</div>

Hi community,

I'm pretty new to ELK and still learning by doing to see if it fits my need.

First of all a bit of background:  
I have a program that will launch a bunch of processes and at the end, I want to generate a report with the execution of my program, the number of successfull/failed processes etc.

I plan to create some documents in Elastic that will have th following type  
ID: int  
EXEC\_DATE: datetime (the date and time the step was launched)  
STEP\_NAME: string (name of the process executed)  
EXEC\_STATUS: string (S for success / F for failure)  
EXEC\_DURATION: datetime with format 'HH:mm:ss' (this represents how long the process ran)  
EXEC\_DURATION\_EPOCH: long (translation of the duration in epoch in case I need it)

Let's imagine I have the following entries  
1 | 2016/02/15 11:00:00 | step\_1 | S | 00:15:00 |   
2 | 2016/02/15 11:15:00 | step\_2 | F | 00:35:00 |   
3 | 2016/02/15 11:50:00 | step\_3 | S | 01:10:00 |   
4 | 2016/02/15 13:50:00 | step\_4 | S | 00:05:00 | ...

based on that input I'd like a line plot with:  
1st value = 00:15:00  
2nd value=00:50:00 (duration of 1 + duration of 2)  
3rd value=02:00:00 (duration of 1 + duration of 2 + duration of 3)  
4th value=02:05:00 (duration of 1 + duration of 2 + duration of 3 + duration of 4)

and on the other hand, I'd like a histogram bar with a size of 4 (4 steps) that cumulates:  
3 green units because I have 3 successfull step and 1 red unit because I have 1 failed steps.

Thanks all for your feedback.

Simon

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 15, 2016, 4:13pm UTC](https://discuss.elastic.co/t/is-it-possible-to-dynamically-aggregate-time/41767/2 "2016-02-15T16:13:30Z")

</div>

This sort of thing isn't really possible at this stage.

---

<div class="post-metadata">

**Author:** ![Sauha](https://avatars.discourse-cdn.com/v4/letter/s/ee7513/32.png) [@Sauha](https://discuss.elastic.co/u/Sauha)\
**Post date:** [February 16, 2016, 10:12am UTC](https://discuss.elastic.co/t/is-it-possible-to-dynamically-aggregate-time/41767/3 "2016-02-16T10:12:04Z")

</div>

Thanks Mark for your feedback.

I'm just doing another where I'm doing the cumulative duration in my code.

So now I have 3 documents looking like this  
1 | 2016/02/15 11:00:00 | step\_1 | S | 00:15:00 | 00:15:00  
2 | 2016/02/15 11:15:00 | step\_2 | F | 00:35:00 | 00:50:00  
3 | 2016/02/15 11:50:00 | step\_3 | S | 01:10:00 | 02:00:00  
4 | 2016/02/15 13:50:00 | step\_4 | S | 00:05:00 |02:05:00

I injected those data in elastic and now want to visualize the last column (Y-axis) based on the 2nd column (X-axis)

I tested my first 'visualization' and notice the Y-axis must 'aggregate' data, can't I just graph the raw values?

Simon

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:02pm UTC](https://discuss.elastic.co/t/is-it-possible-to-dynamically-aggregate-time/41767/4 "2017-07-06T14:02:10Z")

</div>


