# Network I/O Timelion show crazy with offset one second

**URL:** <https://discuss.elastic.co/t/network-i-o-timelion-show-crazy-with-offset-one-second/103284>\
**Category:** Kibana\
**Created:** [October 10, 2017, 3:02am UTC](https://discuss.elastic.co/t/network-i-o-timelion-show-crazy-with-offset-one-second/103284 "2017-10-10T03:02:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RomainXie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romainxie/32/22427_2.png) [@RomainXie](https://discuss.elastic.co/u/RomainXie)\
**Post date:** [October 10, 2017, 3:02am UTC](https://discuss.elastic.co/t/network-i-o-timelion-show-crazy-with-offset-one-second/103284/1 "2017-10-10T03:02:51Z")

</div>

I got the followed graphic:

 ![19](https://us1.discourse-cdn.com/elastic/original/3X/1/8/18a7c782e5b2ec97126832334cdc6c7d1a1c35c5.png)

From the data:

 ![30](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3cad43f51f1de4e8470f0cc0ad74351dbe6e4560.png)

Query:

> .es(kibana=true, index=metricbeat-\*, timefield=@timestamp,  
> metric='sum:system.network.out.bytes', q='system.network.name:eth0')  
> .mvavg(1m)  
> .derivative()  
> .scale\_interval(1s)  
> .if(operator=lt, if=0, then=0)  
> .multiply(8)  
> .lines(width=2)  
> .color(#508ef2)  
> .label(out)  
> .yaxis(units=bits/s)  
> .legend(columns=2, position=ne)

Ps. formated code for view

It seems because the metricbeat got the data delayed ONE secend.

And then, try the 2 mins interval:

 ![04](https://us1.discourse-cdn.com/elastic/original/3X/1/4/14527d264c4767df2d072460cd29f7a311370a94.png)

The problem is same, but only the maximum is average. I had change the mvavg(2m).

I think it maybe a zero data problem. but after I set the interval to one second for recently. It look better.

 ![37](https://us1.discourse-cdn.com/elastic/original/3X/2/6/264caceb7ca36d559b41ec1883072d6b4d9e681d.png)

How could I resolve this problem?

Is a way to filter the data over a error thresholds?

Thanks for any information.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [October 24, 2017, 6:47pm UTC](https://discuss.elastic.co/t/network-i-o-timelion-show-crazy-with-offset-one-second/103284/2 "2017-10-24T18:47:15Z")

</div>

Sorry, but it is not very clear what your question is.

In the first 2 charts, there is a spike that seems to make the other data with lower values not visible.

You can set a limit on the data bounds in the `q` parameter of the `.es` function, with something like:

```auto
q='system.network.name:eth0 AND system.network.out.bytes:[0 TO 1000000]'

```

> [@RomainXie](#):
>
> I think it maybe a zero data problem. but after I set the interval to one second for recently. It look better.

To me, it looks like that chart is showing more consistent data because the time frame is "Last 15 minutes" instead of "Last 4 hours"

---

<div class="post-metadata">

**Author:** ![RomainXie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romainxie/32/22427_2.png) [@RomainXie](https://discuss.elastic.co/u/RomainXie)\
**Post date:** [October 25, 2017, 4:25am UTC](https://discuss.elastic.co/t/network-i-o-timelion-show-crazy-with-offset-one-second/103284/3 "2017-10-25T04:25:41Z")

</div>

Hi, @tsullivan

Thank for your answer.  
It isn't a data problem, it's a collection time problem.  
We write some script for this, and it has been solved. 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2017, 4:39am UTC](https://discuss.elastic.co/t/network-i-o-timelion-show-crazy-with-offset-one-second/103284/4 "2017-11-22T04:39:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
