# Json input kibana calculations

**URL:** <https://discuss.elastic.co/t/json-input-kibana-calculations/130128>\
**Category:** Kibana\
**Created:** [May 1, 2018, 2:29pm UTC](https://discuss.elastic.co/t/json-input-kibana-calculations/130128 "2018-05-01T14:29:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![annk](https://avatars.discourse-cdn.com/v4/letter/a/c68b51/32.png) [@annk](https://discuss.elastic.co/u/annk)\
**Post date:** [May 1, 2018, 2:29pm UTC](https://discuss.elastic.co/t/json-input-kibana-calculations/130128/1 "2018-05-01T14:29:27Z")

</div>

Hi,

I am trying to plot a graph for mean time to failure , I have a watcher setup for this purpose which will give me alerts coming from different hosts .

I have got a line chart with count on Y axis and date histogram on x axis.  
If I have Count 5000(Number of alerts) on a given day , how do I use json script to get MTTF= unique number of hosts / count ?

Any help appreciated.

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [May 1, 2018, 4:57pm UTC](https://discuss.elastic.co/t/json-input-kibana-calculations/130128/2 "2018-05-01T16:57:38Z")

</div>

Hey @annk

I'm pretty sure you won't be able to calculate `unique number of hosts` / `count` in the standard Kibana visualizations, but it's pretty trivial to do with timelion:

```auto
.divide(.es(*, index=logstash*, metric=count), .es(*, index=logstash*, metric=cardinality:clientip))

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/7/07153604f9176efb64671f31cd8b48a8a05e0791.png)

---

<div class="post-metadata">

**Author:** ![annk](https://avatars.discourse-cdn.com/v4/letter/a/c68b51/32.png) [@annk](https://discuss.elastic.co/u/annk)\
**Post date:** [May 2, 2018, 9:00am UTC](https://discuss.elastic.co/t/json-input-kibana-calculations/130128/3 "2018-05-02T09:00:37Z")

</div>

Thanks , This is what I have been looking for.  
But does aggregation works for a text field ? I can only see number fields appearing in metric aggregations.

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [May 2, 2018, 5:53pm UTC](https://discuss.elastic.co/t/json-input-kibana-calculations/130128/4 "2018-05-02T17:53:13Z")

</div>

Which aggregtation? The `metric=cardinality:clientip`? I'm using an ip address there, keyword fields should be available too.

---

<div class="post-metadata">

**Author:** ![annk](https://avatars.discourse-cdn.com/v4/letter/a/c68b51/32.png) [@annk](https://discuss.elastic.co/u/annk)\
**Post date:** [May 3, 2018, 11:02am UTC](https://discuss.elastic.co/t/json-input-kibana-calculations/130128/5 "2018-05-03T11:02:45Z")

</div>

Yes , its working now . When I entered metric=cardinality:beat. , the suggestion list was empty which confused me.

es(_, index=metricbeat-_, metric=cardinality:beat.hostname) this worked for me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2018, 11:02am UTC](https://discuss.elastic.co/t/json-input-kibana-calculations/130128/6 "2018-05-31T11:02:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
