# Kibana Visualization

**URL:** <https://discuss.elastic.co/t/kibana-visualization/251437>\
**Category:** Kibana\
**Created:** [October 8, 2020, 12:38pm UTC](https://discuss.elastic.co/t/kibana-visualization/251437 "2020-10-08T12:38:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sh3ldoris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sh3ldoris/32/76665_2.png) [@Sh3ldoris](https://discuss.elastic.co/u/Sh3ldoris)\
**Post date:** [October 8, 2020, 12:38pm UTC](https://discuss.elastic.co/t/kibana-visualization/251437/1 "2020-10-08T12:38:25Z")

</div>

Hi everyone,  
I'm using Kibana 7.9.2 and I've made this query in DevTools console:

```auto
POST audit/_search
{
  "size": 0,
  "aggs": {
    "sales_per_month": {
      "date_histogram": {
        "field": "timestamp",
        "calendar_interval": "month"
      },
      "aggs": {
        "DOT_START": {
          "filter": {
            "term": {
              "type": "DOT_START"
            }
          },
          "aggs": {
            "my_count": {
              "value_count": {
                "field": "type"
              }
            }
          }
        },
        "DOT_FAILED_TIMEOUT": {
          "filter": {
            "term": {
              "type": "DOT_FAILED_TIMEOUT"
            }
          },
          "aggs": {
            "my_count": {
              "value_count": {
                "field": "type"
              }
            }
          }
        },
        "ROZDIEL": {
          "bucket_script": {
            "buckets_path": {
              "dot_start": "DOT_START>pocet",
              "dot_failed": "DOT_FAILED_TIMEOUT>pocet"
            },
            "script": "params.dot_start - params.dot_failed"
          }
        }
      }
    }
  }
}

```

I'm trying to get count of single values in filed `type`, then I want just subtract them.  
But I need to create some visualization of the subtraction result and I cannot find any solution. Have you guys any suggestions on how I can do it?  
Thans a lot.

---

<div class="post-metadata">

**Author:** ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)\
**Post date:** [October 8, 2020, 3:29pm UTC](https://discuss.elastic.co/t/kibana-visualization/251437/2 "2020-10-08T15:29:28Z")

</div>

Hey @Sh3ldoris,

I didn't dig into details, but it might be that [timelion](https://www.elastic.co/guide/en/kibana/current/timelion.html) is the tool you are looking for.

---

<div class="post-metadata">

**Author:** ![Sh3ldoris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sh3ldoris/32/76665_2.png) [@Sh3ldoris](https://discuss.elastic.co/u/Sh3ldoris)\
**Post date:** [October 9, 2020, 6:48am UTC](https://discuss.elastic.co/t/kibana-visualization/251437/3 "2020-10-09T06:48:04Z")

</div>

Thanks for the quick response,  
but unfortunately, I just want to visualize the result number and as I know timelion is more for working with graphs...I would like to make something like Metric visualization with just number shown.

---

<div class="post-metadata">

**Author:** ![Sh3ldoris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sh3ldoris/32/76665_2.png) [@Sh3ldoris](https://discuss.elastic.co/u/Sh3ldoris)\
**Post date:** [October 9, 2020, 9:19am UTC](https://discuss.elastic.co/t/kibana-visualization/251437/4 "2020-10-09T09:19:55Z")

</div>

So far, I've divided my data into buckets by Term and aggregated by Count:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/0/709ee41b8dc9aa08f2bfbe7dc64548c15283b86d.png)

So is there any way how I can get a count of field `type` for example with value `"DOT_START"`? I mean like in math aggregation where then I could do some subtraction or whatever.

---

<div class="post-metadata">

**Author:** ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)\
**Post date:** [October 12, 2020, 8:53am UTC](https://discuss.elastic.co/t/kibana-visualization/251437/5 "2020-10-12T08:53:42Z")

</div>

@Sh3ldoris, Sorry for the initial confusing with the timelion.

Unfortunately Kibana doesn't fully support bucket\_script aggregations yet. Here is the issue to track: [https://github.com/elastic/kibana/issues/4707](https://github.com/elastic/kibana/issues/4707). But _something_ is possible with TSVB.

I found this example and _I think_ it should be possible in similar fashion to achieve your goal.

1. Create a scripted field or reinvest you documents and add additional fields like: `dotStart: boolean; dotTimeout: boolean`.
2. Use sum aggregation and them bucket script to subtract 2 sums. (Similar as described in [Weighted Average in a DataTable of Kibana](https://discuss.elastic.co/t/weighted-average-in-a-datatable-of-kibana/185909/2))

Maybe there is a simpler way, but, _I think_ suggested way should also work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2020, 8:53am UTC](https://discuss.elastic.co/t/kibana-visualization/251437/6 "2020-11-09T08:53:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
