# Kibana Transforms

**URL:** https://discuss.elastic.co/t/kibana-transforms/321141
**Category:** Kibana
**Tags:** transforms
**Created:** [December 13, 2022, 3:01pm UTC](https://discuss.elastic.co/t/kibana-transforms/321141 "2022-12-13T15:01:32Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![fim01](https://avatars.discourse-cdn.com/v4/letter/f/b4bc9f/32.png) [@fim01](https://discuss.elastic.co/u/fim01)
#### Post date: [December 13, 2022, 3:01pm UTC](https://discuss.elastic.co/t/kibana-transforms/321141/1 "2022-12-13T15:01:32Z")

</div>

I use Pivot to group data within the Transforms section in Kibana.

I'm wondering if its possible to group by a certain field within a defined time intervall?

In my case I would like to group by a field only within a day (00:00 - 24:00). Group by shall split by midnight.

Do you have any hints how to implement this requirement?

Thanks

---

<div class="post-metadata">

### Author: ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)
#### Post date: [December 14, 2022, 6:59am UTC](https://discuss.elastic.co/t/kibana-transforms/321141/2 "2022-12-14T06:59:55Z")

</div>

You can in addition to your existing grouping add a date\_histogram `group_by`:

```auto
    "group_by": { 
      "timestamp": {
        "date_histogram": {
          "field": "timestamp",
          "calendar_interval": "1d"
        }
      },
      "myfield": {
        "terms": {
         ...
        }
      }

```

---

<div class="post-metadata">

### Author: ![fim01](https://avatars.discourse-cdn.com/v4/letter/f/b4bc9f/32.png) [@fim01](https://discuss.elastic.co/u/fim01)
#### Post date: [December 16, 2022, 3:02pm UTC](https://discuss.elastic.co/t/kibana-transforms/321141/3 "2022-12-16T15:02:07Z")

</div>

I'm sorry I'm not so advanced thinker...

I give you more insights bc not able to follow your post.

In Kibana I created Runtime Field using following script:

`emit(doc['@timestamp.max'].value.millis - doc['@timestamp.min'].value.millis)`

The group\_by function is implemented with "Transforms" function. The new index is already prepared.  
I only need to extend the Runtime Field with above functionalitiy: split by midnight or daily buckets.

---

<div class="post-metadata">

### Author: ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)
#### Post date: [December 21, 2022, 8:14am UTC](https://discuss.elastic.co/t/kibana-transforms/321141/4 "2022-12-21T08:14:41Z")

</div>

You can choose a `date_histogram` based `group_by` in the UI:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e4e8242e132520be2df4b3c64f828eac62b2a39.png)

(I clicked on _Add a group by field_)

A runtime field allows you to manipulate single documents, it can not be used to split data sets.

In order to add the `date_histogram` you have to create a new transform, to not start from scratch, select your existing one and choose clone.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 18, 2023, 8:14am UTC](https://discuss.elastic.co/t/kibana-transforms/321141/5 "2023-01-18T08:14:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
