# Metric visualization shows no results instead of 0 in count aggregation with terms exclusion

**URL:** <https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794>\
**Category:** Kibana\
**Created:** [October 12, 2020, 4:27pm UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794 "2020-10-12T16:27:24Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chenlrv](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chenlrv](https://discuss.elastic.co/u/Chenlrv)\
**Post date:** [October 12, 2020, 4:27pm UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/1 "2020-10-12T16:27:24Z")

</div>

Hi,  
I've created a Metric visualization with 2 metrics:

1. Top hit aggregation on "name" field that I have
2. Count aggregation

On top of that I created a filter to get only the results from the recent minute.  
So, I get a count of the distinct names that were present in the recent minute.  
Furthermore, I had to exclude some of these results by a "status" field - I wanted to get the count of the distinct names with that status "error" only.  
So I added a Buckets Terms aggregation with include "ERROR".  
It works well, but when there are no suitable results at all, I get "no results found" in the visualization, which looks quite ugly. I'd like it to show 0. How can I achieve that?  
Is it possible in the metric visualization? If not, is there another visualization that can meet my needs?

Here is the visualization:

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d040357f2293c40c4def945f6c605ba8d447d65.png)

and here it is when no results are found:

![image](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bd550675bc53f8cd3190f074d6af316d9c5e5dc1.png)

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [October 14, 2020, 8:47am UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/2 "2020-10-14T08:47:03Z")

</div>

Hi @Chenlrv can you please tell me if you used the TSVB metric visualization or a standard metric visualization or you created one on Canvas?  
If you can send me also the version of Kibana you are running I can take a look and see if this is actually a bug or something that we haven't think of

---

<div class="post-metadata">

**Author:** ![Chenlrv](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chenlrv](https://discuss.elastic.co/u/Chenlrv)\
**Post date:** [October 14, 2020, 10:25am UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/3 "2020-10-14T10:25:05Z")

</div>

Hi @markov00 , I used the standard metric visualization : ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/e/fe7c5b298e126c631ec9b2ef145246239420e95d.png)

Kibana version is 7.9.0

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [October 14, 2020, 11:32am UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/4 "2020-10-14T11:32:21Z")

</div>

Can you also send me the current configuration on the editor, I'm not sure I've 100% understood how you are configuring this and in particular where you used the top hit aggregation and the terms one.

Because if you are looking to have a metric that describes the number of unique faulty devices, you can simply have a unique count metric aggregation and then apply a filter on the error status code.

---

<div class="post-metadata">

**Author:** ![Chenlrv](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chenlrv](https://discuss.elastic.co/u/Chenlrv)\
**Post date:** [October 14, 2020, 11:47am UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/5 "2020-10-14T11:47:32Z")

</div>

You are right, the top hit aggregation was disabled in the visualization. I use count aggregation with filter on "ERROR" status code

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [October 14, 2020, 12:47pm UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/6 "2020-10-14T12:47:05Z")

</div>

could you please post here the request and response available from the `Inspect` panel because I've tested locally and I can't reproduce the issue:

 ![Screenshot 2020-10-14 at 14.45.47](https://us1.discourse-cdn.com/elastic/original/3X/6/2/627f3e413c4f53582d81b69ced1a374500565fbe.png)

---

<div class="post-metadata">

**Author:** ![Chenlrv](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chenlrv](https://discuss.elastic.co/u/Chenlrv)\
**Post date:** [October 14, 2020, 1:04pm UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/7 "2020-10-14T13:04:53Z")

</div>

Sure, for the exmaple I changed the filter to "WARNING" status (which gives no results found).  
Request:

```auto
   "aggs": {
     "2": {
       "terms": {
         "field": "database.itraffic.status",
         "order": {
           "_key": "desc"
         },
         "size": 5,
         "include": "WARNING"
       }
     }
   },
   "size": 0,
   "stored_fields": [
     "*"
   ],
   "script_fields": {},
   "docvalue_fields": [
     {
       "field": "@timestamp",
       "format": "date_time"
     }
   ],
   "_source": {
     "excludes": []
   },
   "query": {
     "bool": {
       "must": [],
       "filter": [
         {
           "match_all": {}
         },
         {
           "range": {
             "@timestamp": {
               "gte": "now-1m",
               "lt": "now"
             }
           }
         },
         {
           "range": {
             "@timestamp": {
               "gte": "2020-10-14T12:45:40.122Z",
               "lte": "2020-10-14T13:00:40.122Z",
               "format": "strict_date_optional_time"
             }
           }
         }
       ],
       "should": [],
       "must_not": []
     }
   }
 }

```

and response:

````auto
 "took": 21,
 "timed_out": false,
 "_shards": {
   "total": 120,
   "successful": 120,
   "skipped": 112,
   "failed": 0
 },
 "hits": {
   "total": 160,
   "max_score": null,
   "hits": []
 },
 "aggregations": {
   "2": {
     "doc_count_error_upper_bound": 0,
     "sum_other_doc_count": 0,
     "buckets": []
   }
 }
}```
````

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [October 14, 2020, 3:58pm UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/8 "2020-10-14T15:58:39Z")

</div>

Thanks, what is the desired outcome with the specification of the `include: "WARNING"` filter in the terms aggregation? what do you want to achieve with that? because this filters the returned bucket returning only buckets with that specific `status` and in your case seems that you don't have buckets on the selected interval to satisfy that clause: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#\_filtering\_values\_4](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_filtering_values_4)

I'm also seeing that you are specifying also another time filter `last minute` and I think that will not produce the wanted result. I think this can be achieved with TSVB metric visualization as described in this other reply: [Get visualization of missing data](https://discuss.elastic.co/t/get-visualization-of-missing-data/251285/2)

---

<div class="post-metadata">

**Author:** ![Chenlrv](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chenlrv](https://discuss.elastic.co/u/Chenlrv)\
**Post date:** [October 14, 2020, 7:56pm UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/9 "2020-10-14T19:56:22Z")

</div>

I expect that if there are no such results, the metric will show 0 and not "no results found", that's the desired behavior. How can I achieve that? I use last minute filter because I want to show the number of devices that got status error in the last minute

---

<div class="post-metadata">

**Author:** ![Chenlrv](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chenlrv](https://discuss.elastic.co/u/Chenlrv)\
**Post date:** [October 15, 2020, 7:20am UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/10 "2020-10-15T07:20:03Z")

</div>

@markov00 I tried the TSVB metric as you suggested, indeed it almost meets all of my needs - it does show count 0 when there are no results, but the font is too small, and could not find a way to make it bigger.. in the metric visualization the font size is customizable, we want it to look very big.

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [October 15, 2020, 7:39am UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/11 "2020-10-15T07:39:45Z")

</div>

What you can do is to use the same TSVB configuration and use Markdown, you should be able to print out your text and change the css style for that increasing the font size as you prefer.  
Could you please create an enhancement request for the font style/size of TSVB metric here so we can see if we can put that on our roadmap [https://github.com/elastic/kibana/issues/new?template=Feature\_request.md](https://github.com/elastic/kibana/issues/new?template=Feature_request.md)

---

<div class="post-metadata">

**Author:** ![Chenlrv](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chenlrv](https://discuss.elastic.co/u/Chenlrv)\
**Post date:** [October 15, 2020, 7:59am UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/12 "2020-10-15T07:59:28Z")

</div>

@markov00 Markdown also lets me change the background color depends on the count number? I want to background color to be green on 0 and to be red when bigger than 0.

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [October 15, 2020, 9:41am UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/13 "2020-10-15T09:41:11Z")

</div>

I'm sorry, unfortunately not at the moment

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2020, 9:41am UTC](https://discuss.elastic.co/t/metric-visualization-shows-no-results-instead-of-0-in-count-aggregation-with-terms-exclusion/251794/14 "2020-11-12T09:41:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
