# \[NETFLOW\]\[TIMELION\] Bandwitch with netflow packet

**URL:** <https://discuss.elastic.co/t/netflow-timelion-bandwitch-with-netflow-packet/223064>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [March 11, 2020, 8:05am UTC](https://discuss.elastic.co/t/netflow-timelion-bandwitch-with-netflow-packet/223064 "2020-03-11T08:05:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bruno1](https://avatars.discourse-cdn.com/v4/letter/b/b2d939/32.png) [@Bruno1](https://discuss.elastic.co/u/Bruno1)\
**Post date:** [March 11, 2020, 8:05am UTC](https://discuss.elastic.co/t/netflow-timelion-bandwitch-with-netflow-packet/223064/1 "2020-03-11T08:05:17Z")

</div>

Hello,

I Want the timelion bandwitch, but the number of bytes is by connection not by second.

Ex: The connection beetween 192.168.0.1:80 and 192.168.0.1:54220 have begin at 10:00 am and end at 10:05 am. The total of bytes communication is 250 bytes.

Exemple with values of 2 packets :

> Packet 1 :  
> event.start: 10:00  
> event.end: 10:04  
> Network.bytes : 250  
> @Timestamp = event.start

> Packet 2:  
> event.start: 10:10  
> event.end: 10:03  
> Network.bytes : 600  
> @Timestamp = event.start

Me I want the timelion like :

> 10:10 = 50 + 200 bytes  
> 10:11 = 50 + 200 bytes  
> 10:12 = 50 + 200 bytes  
> 10:13 = 50  
> 10:14 = 50

Not like :

> 10:00 : 250 + 600 bytes  
> 10:11= 0  
> 10:12 = 0  
> 10:13 = 0  
> 10:14 = 0

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [March 11, 2020, 5:31pm UTC](https://discuss.elastic.co/t/netflow-timelion-bandwitch-with-netflow-packet/223064/2 "2020-03-11T17:31:40Z")

</div>

Unfortunately I don't think you can accomplish this in Kibana before we support scripted metrics. See [https://github.com/elastic/kibana/issues/2646](https://github.com/elastic/kibana/issues/2646)

---

<div class="post-metadata">

**Author:** ![Bruno1](https://avatars.discourse-cdn.com/v4/letter/b/b2d939/32.png) [@Bruno1](https://discuss.elastic.co/u/Bruno1)\
**Post date:** [March 12, 2020, 8:13am UTC](https://discuss.elastic.co/t/netflow-timelion-bandwitch-with-netflow-packet/223064/3 "2020-03-12T08:13:39Z")

</div>

Hello,

Thanks for you reply, I have found a bypass solution.

It's not optimized but that works.

I use the plugin logstash-filter-ruby on logstash for build 2 news fields:  
1 field with the bandwitch by second and an other with all date on the rang.

> Example :  
> bandwitch\_by\_second : 50  
> timer : { 10:00, 10:01, 10:02, 10:03, 10:04 }

Source code:

```auto
  ruby {
     code => '
     require "date"

     $t1 = DateTime.parse(event.get("[event][start]"))
     $t2 = DateTime.parse(event.get("[event][end]"))
     $t3 = $t2.to_time - $t1.to_time

     event.set("[timer]", [$t1.to_time] )

     if $t3 > 1
       event.set("[network][bytes_by_seconds]", (event.get("[network][bytes]") / $t3).to_i )
       $i = 0
       while $i < $t3 do
         $i += 1
         event.set("[timer]", event.get("[timer]") + [$t1.to_time + $i] )
       end
     else
       event.set("[network][bytes_by_seconds]", event.get("[network][bytes]"))
     end
  '
  }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2020, 8:13am UTC](https://discuss.elastic.co/t/netflow-timelion-bandwitch-with-netflow-packet/223064/4 "2020-04-09T08:13:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
