# Kibana bucket size issue

**URL:** <https://discuss.elastic.co/t/kibana-bucket-size-issue/159605>\
**Category:** Kibana\
**Created:** [December 5, 2018, 9:14pm UTC](https://discuss.elastic.co/t/kibana-bucket-size-issue/159605 "2018-12-05T21:14:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shraddha\_Srivastav](https://avatars.discourse-cdn.com/v4/letter/s/7ba0ec/32.png) [@Shraddha\_Srivastav](https://discuss.elastic.co/u/Shraddha_Srivastav)\
**Post date:** [December 5, 2018, 9:14pm UTC](https://discuss.elastic.co/t/kibana-bucket-size-issue/159605/1 "2018-12-05T21:14:37Z")

</div>

Hi All,

So When I am trying to plot the values of one field with different value for each tag(Please find attached the image of table)

 ![DB%20table%20for%20enumeration](https://us1.discourse-cdn.com/elastic/original/3X/0/5/056a64d93dd4d3aefb03d04ac595a8841f02cb05.jpeg)

For example:  
I have a field called " **Pack\_state**" which has several string values like 'BMU\_State\_Powerdown', 'BMU\_State\_Standby'..and so on. For each value in field **Pack\_State** i want to plot the numeric value of that string i.e. for **BMU\_State\_Standby** I want to plot numeric value 3 under field called **"Value"**.

I am able to plot this in Kibana using Lucene syntax in the script:

**.es(index='enum', timefield='TimeOfDay',q='BMU\_Debug\_Pack\_State:BMU\_State\_Standby', metric='max:Value').label('BMU\_State\_Standby'),**  
**.es(index='enum', timefield='TimeOfDay',q='BMU\_Debug\_Pack\_State:BMU\_State\_Drive', metric='max:Value').label('BMU\_State\_Drive')**

 ![Kibana%20overlay%20values](https://us1.discourse-cdn.com/elastic/original/3X/7/b/7bb6e157d688787e4f78649c0a222ef28adfb5d6.png)

 ![kibana%20false%20value](https://us1.discourse-cdn.com/elastic/original/3X/7/4/741e274e161ca7f314cc596324a8ba230ec34bc7.png)

**(In the above picture you can see the value for BMU\_State\_Drive starts showing much much before it actually should) HOW TO SOLVE THIS ? WHAT REGEX SHOULD I USE?**

I am able to achieve the numeric values(2,3,4,...) with the string as its label using lucene syntax in kibana (as i have shared above the script for Timelion) but the problem is at one timestamp( **i.e. 11:15:54.551** ) it shows me 2 numeric values for both the strings, However if u look at the image 'BMU\_State\_Drive' ( **the red line** ) value does not even start at that time but still displaying the numeric value thereby confusing the people viewing the dashboard. I guess it the bucket size issue as kibana doesnt find any data points to show it retains the last value and display that untill at a new timestamp it finds a new value.(I am not sure why its showing this behavior).

I hope I was able to clear myself. Let me know if it's still not clear. Please help. Thank You in advance 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2019, 9:14pm UTC](https://discuss.elastic.co/t/kibana-bucket-size-issue/159605/2 "2019-01-02T21:14:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
