# Kibana: how to calculate a delta metric in table visualization?

**URL:** <https://discuss.elastic.co/t/kibana-how-to-calculate-a-delta-metric-in-table-visualization/73646>\
**Category:** Kibana\
**Created:** [February 2, 2017, 9:37am UTC](https://discuss.elastic.co/t/kibana-how-to-calculate-a-delta-metric-in-table-visualization/73646 "2017-02-02T09:37:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [February 2, 2017, 9:37am UTC](https://discuss.elastic.co/t/kibana-how-to-calculate-a-delta-metric-in-table-visualization/73646/1 "2017-02-02T09:37:51Z")

</div>

Hi,

I have logs, which contain statistical absolute values.  
Each minute I get the statistics, how many transactions a service has processed since start of the service.  
So it is a steadily growing number until the next restart of the server.

Now I want to know, how many transactions have been processed per service in the selected timeframe.  
My idea is to create a table visualization, returning min and max of the processed transactions.

Now I also want to add the result of (max - min) and add it as column to the table.  
How can I do that?  
Is there something built in?  
Can I easily create custom aggregations?

Target is kibana 5.1. If there is a way to use in kibana 4.1 it is also welcomed, because i have not finished yet the upgrade to elk 5.1 yet.

Thanks, Andreas

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [February 2, 2017, 4:31pm UTC](https://discuss.elastic.co/t/kibana-how-to-calculate-a-delta-metric-in-table-visualization/73646/2 "2017-02-02T16:31:48Z")

</div>

This isn't currently possible in core Kibana, here's an open ticket [https://github.com/elastic/kibana/issues/2805](https://github.com/elastic/kibana/issues/2805)

However, you could easily accomplish this in Timelion. The query would look like this:

```auto
.es(*, metric='max:bytes').subtract(.es(*, metric='min:bytes'))

```

Just replace `bytes` with whatever your field name is.

Here's an example with the min, max, and difference between the two:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/4fd0b3c648a56c449febd1855582f0da1060bb86.png)

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [February 13, 2017, 8:14am UTC](https://discuss.elastic.co/t/kibana-how-to-calculate-a-delta-metric-in-table-visualization/73646/3 "2017-02-13T08:14:45Z")

</div>

thanks for the response. But that's not what i need.

I need the diffrence of the values from different times.  
Value of last event - value of first event.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [February 13, 2017, 3:48pm UTC](https://discuss.elastic.co/t/kibana-how-to-calculate-a-delta-metric-in-table-visualization/73646/4 "2017-02-13T15:48:37Z")

</div>

Hi @asp

Perhaps I've misunderstood what your data looks like. You mentioned:

> Each minute I get the statistics, how many transactions a service has processed since start of the service.  
> So it is a steadily growing number until the next restart of the server.

If the transaction count field is always increasing, won't the minimum and maximum count be the first and last events by definition, except perhaps after a restart?

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [February 16, 2017, 2:51pm UTC](https://discuss.elastic.co/t/kibana-how-to-calculate-a-delta-metric-in-table-visualization/73646/5 "2017-02-16T14:51:07Z")

</div>

yes, exactly. Let me do an example.

```
minute 0: 0 processed
minute 1: 100 processed
minute 2: 150 processed
minute 3: 150 processed
minute 4: 200 processed
minute 5: 600 processed
minute 6: 620 processed

```

Now I set my time interval vor analysis to minutes 2 to 5.  
min value is 150, max value is 600.  
What I need to show is is 450 as difference (600 - 150 = 450)

In your screenshot the difference is calculated from min and max of the same time. That's why your diff is a curve and not a constant.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [February 16, 2017, 7:46pm UTC](https://discuss.elastic.co/t/kibana-how-to-calculate-a-delta-metric-in-table-visualization/73646/6 "2017-02-16T19:46:22Z")

</div>

> [@asp](#):
>
> In your screenshot the difference is calculated from min and max of the same time.

That's not true. The difference is calculated from the same _interval_. To demonstrate, see the screenshot below. I've set my interval to 1 day and I'm charting the min and max timestamp for each interval. So the red line represents the first document in each bucket and and the blue line is the last document. If you set your interval to "3 minutes" and start the time range at minute two, you'll see the difference between minute 5 and minute 2 charted in the first graph I proposed.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/201d7a87aceb2a9f24cac3bfa0a637214af47c2d.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2017, 7:46pm UTC](https://discuss.elastic.co/t/kibana-how-to-calculate-a-delta-metric-in-table-visualization/73646/7 "2017-03-16T19:46:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
