# Kibana Semaphore - no logs in 5min, 10min, 30min

**URL:** <https://discuss.elastic.co/t/kibana-semaphore-no-logs-in-5min-10min-30min/373892>\
**Category:** Kibana\
**Created:** [January 30, 2025, 12:40pm UTC](https://discuss.elastic.co/t/kibana-semaphore-no-logs-in-5min-10min-30min/373892 "2025-01-30T12:40:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rnx](https://avatars.discourse-cdn.com/v4/letter/r/6de8d8/32.png) [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Post date:** [January 30, 2025, 12:40pm UTC](https://discuss.elastic.co/t/kibana-semaphore-no-logs-in-5min-10min-30min/373892/1 "2025-01-30T12:40:32Z")

</div>

How to create any kind of vizualisation in Kibana, which change the color according to amount of logs in time. Let's say, it should be green if there is any amount of logs within 5minutes, if no log is present in 5 mins, it should turn to Orange, if no logs are present in 30 minutes, then let it turn to red.  
I prefer some kind of semaphore, however, it could be anything, which could be saved to dashboard.

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [January 30, 2025, 3:27pm UTC](https://discuss.elastic.co/t/kibana-semaphore-no-logs-in-5min-10min-30min/373892/2 "2025-01-30T15:27:39Z")

</div>

Hi @Rnx

would something like this work?

 ![Screenshot 2025-01-30 at 16.21.34](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e318afdcfd9bd8de82ac591d894651e826c8ade6.png)

The numbers there `0`, `1`, `2` are used to colour correctly the tile, but have no metric value unfortunately.  
To build that I've created a Metric chart in Lens and defined the primary metric as follow with Lens formula:

```auto
ifelse(count(reducedTimeRange='5m') > 0, 2, ifelse(count(reducedTimeRange='30m') > 0, 1, 0))

```

That reflects you logic, using the 0, 1, 2 to encode the different output types: if the `count` in the last 5 minutes is greater than 0, then mark it as 2, otherwise if count in the last 30 minutes is greater than 0 mark it as 1, else 0.  
Note I've set the label to empty string ` ` to avoid too much clutter in the tiles.  
Then I've configured a dynamic colouring logic as follow:

 ![Screenshot 2025-01-30 at 16.22.06](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1cd11c5f07d40cd1d1a984360078cfd9623207d4.png)

And at last a breakdown metric by IP:

 ![Screenshot 2025-01-30 at 16.21.49](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4a38e34ad6e5c54d0d3ea70d82ccf897d7f52c6a.png)

Make sure to configure in the breakdown the number of columns to something more than 3.

You could potentially configure a secondary metric to show the last timestamp for the client ip if you want.

Hope it helps.

---

<div class="post-metadata">

**Author:** ![Rnx](https://avatars.discourse-cdn.com/v4/letter/r/6de8d8/32.png) [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Post date:** [January 30, 2025, 4:17pm UTC](https://discuss.elastic.co/t/kibana-semaphore-no-logs-in-5min-10min-30min/373892/3 "2025-01-30T16:17:14Z")

</div>

Hi, helped a little, I forgot there is a formula in "Metric" diagram. There could be million records of logs as well as none, so I was looking for something like "least effort", that means no data parsing or scripting. I found out there is now() function and is possible to compare it with @timestamp.  
The outcome is formula:  
`abs((now() - last_value(@timestamp) - 3600) / 1000)`  
where abs() can be omitted, 3600 is time zone shift (dirty solution) and / 1000 removes milliseconds.  
Result is count of seconds, which can be freely marked or painted within the metric diagram.

 ![Screenshot 2025-01-30 at 17.14.01](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c69ca75714f86828aeed85dda17154a5ca27a8b6.png)
