# Plot values for a single field over time

**URL:** <https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914>\
**Category:** Kibana\
**Tags:** visualisation\
**Created:** [July 7, 2023, 6:55pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914 "2023-07-07T18:55:14Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ryan\_Downey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_downey/32/35987_2.png) [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Post date:** [July 7, 2023, 6:55pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914/1 "2023-07-07T18:55:14Z")

</div>

All I'm looking to do is create a line visualization where the 5\_sec\_eps field displays its values. 5\_sec\_eps on the Y axis and time on the bottom. Thats all I need, thank you.

 ![5_sec_eps](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8bf8aaadba0d0ba1db5aca2fd96f375bdcaafddd.jpeg)

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 12, 2023, 4:52pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914/2 "2023-07-12T16:52:00Z")

</div>

Hi, there is an excellent article written by a former Kibana contributor that explains how to add a scatterplot visualization: [Scatterplot in Kibana using Vega » Tim Roes](https://www.timroes.de/kibana-vega-scatterplot)

The Kibana tool to achieve this is Vega, the documentation is here: [Vega | Kibana Guide [8.8] | Elastic](https://www.elastic.co/guide/en/kibana/current/vega.html)

---

<div class="post-metadata">

**Author:** ![Ryan\_Downey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_downey/32/35987_2.png) [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Post date:** [July 17, 2023, 1:52pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914/3 "2023-07-17T13:52:03Z")

</div>

Tim,  
Thank you for the reply. I'll look through this today and also work on getting the data in correctly. The numbers may be being stored as a string which may be why I've been having such a hard time getting a basic dashboard to populate. I'm going to look at turning these into integers instead of a string if that actually is the problem.  
Ryan

---

<div class="post-metadata">

**Author:** ![Ryan\_Downey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_downey/32/35987_2.png) [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Post date:** [July 18, 2023, 1:32pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914/4 "2023-07-18T13:32:05Z")

</div>

Tim,  
I've got the ingest pipeline changing the value for 5\_sec\_eps from a string to a float with the convert processor. I've also been able to build a Vega (Lite?) visualization but can't figure out how to get the data displayed correctly. The goal is to display the eps values for each of the DLC's we have in a line chart. The issue I'm hitting is that its displaying a literal straight line (see image).

Code so far:

```auto
{
  "$schema": "https://vega.github.io/schema/vega-lite/v2.json",
  "mark": "line",
  "data": {
    "url": {
      "%context%": true,
      "%timefield%": "@timestamp",
      "index": "lab-dlc-eps-data",
      "body": {
        "size": 10000,
        "_source": ["@timestamp", "5_sec_eps", "kubernetes.pod.name"]
      }
    },
    "format": {"property": "hits.hits"}
  },
  "transform": [
    {
      "calculate": "toDate(datum._source['@timestamp'])",
      "as": "time"
    }
  ],
  "encoding": {
    "x": {
      "field": "_source.kubernetes.pod.name",
      "type": "nominal",
      "axis": {
        "title": "Pod Name"
      }
    },
    "y": {
      "field": "_source.5_sec_eps",
      "type": "quantitative",
      "axis": {
        "title": "5 Sec EPS"
      }
    }
  }
}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/2/a21abbf1ed0852d96cc5483c01cb124065ff8d68.png)

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [July 19, 2023, 9:34am UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914/5 "2023-07-19T09:34:07Z")

</div>

Hi @Ryan_Downey, why not use Lens for your case? Vega is not a trivial solution and needs some time to master.

You mention you want a line visualization, so I understand you have one value of `5_sec_ops` per time interval, or you are OK with doing an aggregation if there is more than one data point.

Just to compare, I created a simple Vega line chart from the Kibana Flights data sample with the following definition:

```json
{
  "$schema": "https://vega.github.io/schema/vega-lite/v5.json",
  "title": "Ticket prices at Kibana Sample Data Flights",
  "data": {
    "url": {
      "%context%": true,
      "%timefield%": "timestamp",
      "index": "kibana_sample_data_flights",
      "body": {
        "aggs": {
          "time_buckets": {
            "date_histogram": {
              "field": "timestamp",
              "interval": {"%autointerval%": true},
              "time_zone": "Europe/Madrid",
              "extended_bounds": {
                "min": {"%timefilter%": "min"},
                "max": {"%timefilter%": "max"}
              },
              "min_doc_count": 0
            },
            "aggs": {"avg_avgticketprice": {"avg": {"field": "AvgTicketPrice"}}}
          }
        },
        "size": 0
      }
    },
    "format": {"property": "aggregations.time_buckets.buckets"}
  },
  "mark": "line",
  "encoding": {
    "x": {"field": "key", "type": "temporal", "axis": {"title": false}},
    "y": {
      "field": "avg_avgticketprice.value",
      "type": "quantitative",
      "axis": {"title": "Average of AvgTicketPrice"}
    }
  }
}

```

This chart does not have any interactivity, tooltips, etc.

Showing it alongside the Lens chart you can see how Lens does a way better job so I'd suggest only going to Vega when there's no other choice.

![Peek 2023-07-19 11-31](https://us1.discourse-cdn.com/elastic/original/3X/e/d/edc2965de83c9c115c496cb1f47dc9a3f6e78b9d.gif)

---

<div class="post-metadata">

**Author:** ![Ryan\_Downey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_downey/32/35987_2.png) [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Post date:** [July 19, 2023, 1:52pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914/6 "2023-07-19T13:52:23Z")

</div>

@jsanz Thank you for the in depth response. I would much prefer to use Lens if its the easiest most efficient route to go. I just haven't had much luck getting the visualization to display what I need so all options were on the table. I'll work through your example today and see where I can get my visualization too.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 19, 2023, 4:58pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914/7 "2023-07-19T16:58:07Z")

</div>

Thanks for the input, Jorge! I probably misunderstood the original topic by proposing a scatter plot chart - sorry about that!

If a line chart suits the use case, using Lens is definitely the way to go.

---

<div class="post-metadata">

**Author:** ![Ryan\_Downey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_downey/32/35987_2.png) [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Post date:** [July 19, 2023, 5:28pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914/8 "2023-07-19T17:28:35Z")

</div>

@tsullivan No worries! I appreciate both of you helping out. Trying to work through the process here. To give more of an idea as to whats going on here, we're ingesting data, using a grok pattern to pull the events per second (eps) values out of the message field and then converting them to a float since they were initially being stored as a string. I thought this would be a pretty easy drag and drop process but I'm hitting the Elastic learning curve. 😀

---

<div class="post-metadata">

**Author:** ![Ryan\_Downey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_downey/32/35987_2.png) [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Post date:** [July 20, 2023, 7:02pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914/9 "2023-07-20T19:02:01Z")

</div>

@jsanz @tsullivan After working through all of the steps and still having some difficulty I've taken a step back to make sure that the data I'm working with is organized correctly first. This may be the underlying problem so I have a ticket open with support but also started a discussion thread called [Convert message into eps data and create a visualization](https://discuss.elastic.co/t/convert-message-into-eps-data-and-create-a-visualization/338903) as well. Thanks for the help and I'll post here if I get this sorted out and the visualization setup.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2023, 7:02pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914/10 "2023-08-17T19:02:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
