# Kibana3 - total of sc-btyes field

**URL:** <https://discuss.elastic.co/t/kibana3-total-of-sc-btyes-field/14929>\
**Category:** Elasticsearch\
**Created:** [December 18, 2013, 10:46am UTC](https://discuss.elastic.co/t/kibana3-total-of-sc-btyes-field/14929 "2013-12-18T10:46:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johnathan\_Phan](https://avatars.discourse-cdn.com/v4/letter/j/e68b1a/32.png) [@Johnathan\_Phan](https://discuss.elastic.co/u/Johnathan_Phan)\
**Post date:** [December 18, 2013, 10:46am UTC](https://discuss.elastic.co/t/kibana3-total-of-sc-btyes-field/14929/1 "2013-12-18T10:46:48Z")

</div>

Hi everyone,

I have a set of logs in ES from cloudfront. I have a field called sc-bytes,  
I want the total from the btyes for a specific subset of data I filter. I  
have tried the following.

Adding a histogram, setting "Chart Value" to "Total". Then setting the  
"Value field" to "sc-bytes".

I get the following exception.

ClassCastException[org.elasticsearch.index.fielddata.plain.PagedBytesIndexFieldData  
cannot be cast to org.elasticsearch.index.fielddata.IndexNumericFieldData]

I have doubel checked this as logstash is setting the value to Number for  
the field sc-bytes. Does anyone know what is wrong here?

Regards

John

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e7809e65-ba37-4821-a3db-63172f05ac2d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e7809e65-ba37-4821-a3db-63172f05ac2d%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Johnathan\_Phan](https://avatars.discourse-cdn.com/v4/letter/j/e68b1a/32.png) [@Johnathan\_Phan](https://discuss.elastic.co/u/Johnathan_Phan)\
**Post date:** [December 18, 2013, 11:00am UTC](https://discuss.elastic.co/t/kibana3-total-of-sc-btyes-field/14929/2 "2013-12-18T11:00:01Z")

</div>

Hi Everyone,

Got a little further.

I made my query have this value.

sc-bytes:\*

As the selected query.

from[-1],size[-1]: Parse Failure [Failed to parse source  
[{"facets":{"0":{"date\_histogram":{"key\_field":"@timestamp","value\_field":"sc-bytes","interval":"12h"},"global":true,"facet\_filter":{"fquery":{"query":{"filtered":{"query":{"query\_string":{"query":"sc-bytes:\*"}},"filter":{"bool":{"must":[{"fquery":{"query":{"field":{"type":{"query":"cloudfront"}}},"\_cache":true}},{"fquery":{"query":{"field":{"PLATFORM":{"query":""test\_system""}}},"\_cache":true}},{"range":{"@timestamp":{"from":1384772252771,"to":"now"}}},{"fquery":{"query":{"field":{"cs-uri-stem":{"query":"_test_"}}},"\_cache":true}}]}}}}}}}},"size":0}]]]

I don't understand this error, can someone help me?

Regards

John

On Wednesday, 18 December 2013 10:46:48 UTC, Johnathan Phan wrote:

> Hi everyone,
> 
> I have a set of logs in ES from cloudfront. I have a field called  
> sc-bytes, I want the total from the btyes for a specific subset of data I  
> filter. I have tried the following.
> 
> Adding a histogram, setting "Chart Value" to "Total". Then setting the  
> "Value field" to "sc-bytes".
> 
> I get the following exception.
> 
> ClassCastException[org.elasticsearch.index.fielddata.plain.PagedBytesIndexFieldData  
> cannot be cast to org.elasticsearch.index.fielddata.IndexNumericFieldData]
> 
> I have doubel checked this as logstash is setting the value to Number for  
> the field sc-bytes. Does anyone know what is wrong here?
> 
> Regards
> 
> John

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/89fbbcfe-0c3b-4513-b6de-b35ea50cd38f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/89fbbcfe-0c3b-4513-b6de-b35ea50cd38f%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Johnathan\_Phan](https://avatars.discourse-cdn.com/v4/letter/j/e68b1a/32.png) [@Johnathan\_Phan](https://discuss.elastic.co/u/Johnathan_Phan)\
**Post date:** [December 18, 2013, 11:04am UTC](https://discuss.elastic.co/t/kibana3-total-of-sc-btyes-field/14929/3 "2013-12-18T11:04:10Z")

</div>

Hi There,

This is the query the histogram is trying to run.

curl -XGET '[http://log-analysis.channel4.com](http://log-analysis.channel4.com):/logstash-2013.12.12,logstash-2013.12.11,logstash-2013.12.10,logstash-2013.12.09,logstash-2013.12.08,logstash-2013.12.07,logstash-2013.12.06,logstash-2013.12.05,logstash-2013.12.04,logstash-2013.12.03,logstash-2013.12.02,logstash-2013.12.01,logstash-2013.11.30,logstash-2013.11.29,logstash-2013.11.28,logstash-2013.11.27,logstash-2013.11.26,logstash-2013.11.25,logstash-2013.11.24,logstash-2013.11.23,logstash-2013.11.22,logstash-2013.11.21,logstash-2013.11.20,logstash-2013.11.19,logstash-2013.11.18/\_search?pretty' -d '{  
"facets": {  
"0": {  
"date\_histogram": {  
"key\_field": "@timestamp",  
"value\_field": "sc-bytes",  
"interval": "12h"  
},  
"global": true,  
"facet\_filter": {  
"fquery": {  
"query": {  
"filtered": {  
"query": {  
"query\_string": {  
"query": "sc-bytes:\*"  
}  
},  
"filter": {  
"bool": {  
"must": [  
{  
"fquery": {  
"query": {  
"field": {  
"type": {  
"query": "cloudfront"  
}  
}  
},  
"\_cache": true  
}  
},  
{  
"fquery": {  
"query": {  
"field": {  
"PLATFORM": {  
"query": ""test\_system""  
}  
}  
},  
"\_cache": true  
}  
},  
{  
"range": {  
"@timestamp": {  
"from": 1384772438978,  
"to": "now"  
}  
}  
},  
{  
"fquery": {  
"query": {  
"field": {  
"cs-uri-stem": {  
"query": "_tt_"  
}  
}  
},  
"\_cache": true  
}  
}  
]  
}  
}  
}  
}  
}  
}  
}  
},  
"size": 0  
}'

On Wednesday, 18 December 2013 10:46:48 UTC, Johnathan Phan wrote:

> Hi everyone,
> 
> I have a set of logs in ES from cloudfront. I have a field called  
> sc-bytes, I want the total from the btyes for a specific subset of data I  
> filter. I have tried the following.
> 
> Adding a histogram, setting "Chart Value" to "Total". Then setting the  
> "Value field" to "sc-bytes".
> 
> I get the following exception.
> 
> ClassCastException[org.elasticsearch.index.fielddata.plain.PagedBytesIndexFieldData  
> cannot be cast to org.elasticsearch.index.fielddata.IndexNumericFieldData]
> 
> I have doubel checked this as logstash is setting the value to Number for  
> the field sc-bytes. Does anyone know what is wrong here?
> 
> Regards
> 
> John

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/d9772acc-5ee5-4479-a889-9d80c824f4ca%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/d9772acc-5ee5-4479-a889-9d80c824f4ca%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:00am UTC](https://discuss.elastic.co/t/kibana3-total-of-sc-btyes-field/14929/4 "2017-07-06T02:00:25Z")

</div>


