# Kibana - range based on count timeseries

**URL:** <https://discuss.elastic.co/t/kibana-range-based-on-count-timeseries/203435>\
**Category:** Kibana\
**Created:** [October 14, 2019, 11:08am UTC](https://discuss.elastic.co/t/kibana-range-based-on-count-timeseries/203435 "2019-10-14T11:08:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![megakoresh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/megakoresh/32/54166_2.png) [@megakoresh](https://discuss.elastic.co/u/megakoresh)\
**Post date:** [October 14, 2019, 11:08am UTC](https://discuss.elastic.co/t/kibana-range-based-on-count-timeseries/203435/1 "2019-10-14T11:08:17Z")

</div>

As continuation of this question: [https://discuss.elastic.co/t/kibana-range-based-on-count/](https://discuss.elastic.co/t/kibana-range-based-on-count/)

I would like to now display this data over time. Kind of like this:

 ![09](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8ba3241a83f5d251acc29a0a5ce2730bc12de673.png)

Which is backed by the following expression:

```
filters
| essql 
  query="SELECT COUNT(*) as patches_applied, hostname, source, HISTOGRAM(timestamp, INTERVAL 1 DAY) as hist 
FROM \"vulnerability-report\" 
WHERE 
(\"vulnerability-report\".os != 'Unknown')
GROUP BY hostname,hist,source" count=5000
| mapColumn "range"
  fn={getCell "patches_applied" | switch case={case if={all {gte 0} {lt 10}} then="0-10"} case={case if={all {gte 10} {lt 50}} then="10-50"} case={case if={all {gte 50} {lt 100}} then="50-100"} default="100+"}
| sort by="range"
| pointseries x="hist" y="unique(hostname)" color="range"
| plot defaultStyle={seriesStyle lines=2 fill=1 stack=1} 
  palette={palette "#1ea593" "#2b70f7" "#ce0060" "#38007e" "#fca5d3" "#f37020" "#e49e29" "#b0916f" "#7b000b" "#34130c" gradient=false}
| render

```

However there is a big problem in that this `count` parameter, when set to high enough value, simply crashes the browser. In this case, the unique combinations of `hostname`, `hist` and`source` taken over that period of time amount to over 20000 entries (overall number of documents over that time period is little over 2 million) and that's enough to crash the browser.

Is it maybe possible in timelion?

I could not find any way filter on aggregated count in timelion.

The screenshot above is correct structurally but is basically only showing a subset of the data ordered by hostname, and does not accurately represent the situation

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [October 14, 2019, 11:52am UTC](https://discuss.elastic.co/t/kibana-range-based-on-count-timeseries/203435/2 "2019-10-14T11:52:52Z")

</div>

if i understand the issue the problem is that essql returns too many rows, which crashes the browser ? does pointseries return less data then ?

i don't think there is a way to do that in timelion.

---

<div class="post-metadata">

**Author:** ![megakoresh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/megakoresh/32/54166_2.png) [@megakoresh](https://discuss.elastic.co/u/megakoresh)\
**Post date:** [October 14, 2019, 11:59am UTC](https://discuss.elastic.co/t/kibana-range-based-on-count-timeseries/203435/3 "2019-10-14T11:59:20Z")

</div>

Seems that it does, yes. I don't know how this `count` parameter works or how it limits the results. The correct way would be to aggregate this data so that records are transformed to timeseries points, instead of processing the whole set one record at a time, but I am not sure where to begin with that.

I basically need to operate on the `doc_count` value of cardinality aggregation, which ESSQL exposes thanks to it's table formatting. For this use-case though, I need to somehow get kibana to map this value over time for each of those ranges using aggregations.

PS:

If it worked, this would give me what I need:

 ![57](https://us1.discourse-cdn.com/elastic/original/3X/c/0/c0561e2c6de03a84bbaaa6039cc8406c8d160115.png)  
Sadly it doesn't. Is there a way to do this somehow? Maybe via scripts? It's very hard to know how to apply techniques outlined in Elasticsearch aggregation documentation for Kibana visualizations.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2019, 12:02pm UTC](https://discuss.elastic.co/t/kibana-range-based-on-count-timeseries/203435/4 "2019-11-11T12:02:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
