# Multiline graph over time

**URL:** <https://discuss.elastic.co/t/multiline-graph-over-time/108452>\
**Category:** Kibana\
**Created:** [November 20, 2017, 8:13pm UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452 "2017-11-20T20:13:55Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)\
**Post date:** [November 20, 2017, 8:13pm UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/1 "2017-11-20T20:13:56Z")

</div>

I have the following pertinent document properties:

```auto
...
    "properties": {
        "timestamp": { "type": "date"},
        "event": { "type": "text"}, // various *_BEGIN/END events
        "resource_id": {"type": "text"},
        "elapsed_time": {"type": "float"}
    }
...

```

I'm able to generate a pie chart of average durations spent between multiple begin/end event pairs for a specific resource\_id. Looks great and is averaged over whatever timespan I want to view. It shows me basically how much time (on average) is spent on various calculations for a particular `resource_id`  
 ![47 AM](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6d5d86b6167b52ef1d2479d60f1261fedb2c7753.png)

However, I'd now like to create a multi-line graph of these various duration categories over time. I want to see a single line for each category (Garnish, Overpayment, etc) aggregated daily. I can't quite figure out how to do this, but I think I need a Line graph with 14 different lines (I'll most likely reduce this to 3-5 key measures to be easier on the eyes), and I think I may need sibling or parent pipelines... but not sure.

Could you provide any tips for how I might create that line graph? What types of aggregations and parent/sibling pipelines, or "term" vs "filter" filters might I need?

Thanks much! Having a great time learning to use this tool.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [November 21, 2017, 4:50pm UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/2 "2017-11-21T16:50:37Z")

</div>

Hi John, can you supply a screenshot of what the visualization builder looks like that created the pie chart, and also perhaps a few samples of documents that are in your index? I'd like to help but I think I'm stuck on what the `event` data looks like.

---

<div class="post-metadata">

**Author:** ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)\
**Post date:** [November 21, 2017, 7:24pm UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/3 "2017-11-21T19:24:27Z")

</div>

Thanks so much for your offer to help @tsullivan. Do these help?

The visualization of the pie chart:

 ![06 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0fbedd9e7ed1edb24b04d7d6b047a696e23cab6b.png)

Some events and the pertinent log lines:

 ![45 AM](https://us1.discourse-cdn.com/elastic/original/3X/c/7/c77d15371ca708358fad43f11094acb57783c39a.png)

I've picked a single resource\_id and have shown all the events on that resource. Other resource's have the same events and calculations for elapsed time. I want to show how those elapsed\_time averages change over the week using a line graph. For example, I'd be able to see how the system spends time (on average) for the CALC\_WCI\_\* process across all tracked resources. It wouldn't even have to be an "average" time and could just be total time if that's easier. I just need a sense of how the time spent between paired events changes over time. Make sense?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [November 21, 2017, 10:38pm UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/4 "2017-11-21T22:38:43Z")

</div>

> [@joconner](#):
>
> I just need a sense of how the time spent between paired events changes over time.

It looks like you really just need to look at the elapsed time field of the `*_END` fields for this - based on the observation that field is null for the other events, and your filters aggregation only uses the `*_END` fields.

The way you would do this in a Line Chart is very similar to what you did for the pie chart, except there is a Date Histogram aggregation that makes time buckets for a regular interval of dates.

Thanks to your mapping and the sample data, I made a date histogram line chart that I think does what you're looking for:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/7/47a07ebcc57ef4fa4d3b14ed98667572d33243d0.png)

Sorry, the data I indexed is not very continuous so it segments all over the place. Hopefully this conveys the idea though.

---

<div class="post-metadata">

**Author:** ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)\
**Post date:** [November 21, 2017, 10:49pm UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/5 "2017-11-21T22:49:24Z")

</div>

Wow @tsullivan, you've really helped. AND I didn't realize that the "filters" needed to be in that syntax. Makes me think I need to redo the pie chart to use that syntax. I just used `CALC_UNION_END` instead of `event:CALC_UNION_END` for example in the filters.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [November 21, 2017, 10:52pm UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/6 "2017-11-21T22:52:44Z")

</div>

When you don't specify a field name in the filter, Elasticsearch uses the `_all` field which I tend to avoid for performance reasons:

- [https://www.elastic.co/guide/en/kibana/current/lucene-query.html](https://www.elastic.co/guide/en/kibana/current/lucene-query.html)
- [https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html)

BTW I mixed up my data a bit more, and got my line chart working a little easier by splitting using a `terms` aggregation instead of a `filters`:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f242249eba3356681b1d18fd9318a3bd59bcc374.png)

---

<div class="post-metadata">

**Author:** ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)\
**Post date:** [November 21, 2017, 11:05pm UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/7 "2017-11-21T23:05:34Z")

</div>

Can you share how `terms` vs `filters` works? How are they different? How does it affect the chart?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [November 21, 2017, 11:13pm UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/8 "2017-11-21T23:13:04Z")

</div>

Terms aggregation: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html)

Filters aggregation: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-filters-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-filters-aggregation.html)

In a terms agg, the buckets are built dynamically based on what terms are found, in this case for each time bucket provided by the date histogram aggregation. The line chart only renders data for the terms that are present for each time bucket, so it'll show gaps in the chart when there isn't a term for a particular time bucket.

In a filters agg, it looks for all the terms you give it in each time bucket. That's why it shows zeroes when a term doesn't have any data for a particular time bucket.

---

<div class="post-metadata">

**Author:** ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)\
**Post date:** [November 22, 2017, 10:34pm UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/9 "2017-11-22T22:34:31Z")

</div>

Thanks again @tsullivan. Last question on this:  
I'd like to calculate the _sum_ of the 2 averages on this graph. What would be the magic to do that? I've tried adding a Y-axis with a "Sum" calculation on the `elapsed_time` but that's just completely wrong. God, there are a lot of options. I know how I need to spend my weekend.

Here's the current visualization details:

 ![54 PM](https://us1.discourse-cdn.com/elastic/original/3X/5/8/5885799829012673dd0227accb1b6e0f0f419618.png)

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [November 23, 2017, 12:17am UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/10 "2017-11-23T00:17:39Z")

</div>

I think you can use the Time Series Visual Builder here. I'm a little out of my depth here though because my test data I put in isn't very good and I wasn't able to get something working.

- in Panel Options, set your index and time field

- in the Data panel, make an average of `elapsed_time`, chain it to an Overall Sum

- the Group By is going to be your filters

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/1/8169d1ceed7eb1c9754bf73c7f6930fcfb33ee8e.png)

There's some helpful guidance in the blog article written about TSVB: [https://www.elastic.co/blog/master-time-with-kibanas-new-time-series-visual-builder](https://www.elastic.co/blog/master-time-with-kibanas-new-time-series-visual-builder)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2017, 12:10am UTC](https://discuss.elastic.co/t/multiline-graph-over-time/108452/12 "2017-12-26T00:10:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
