# Refresh the current status OR only show/hide elements of choice

**URL:** <https://discuss.elastic.co/t/refresh-the-current-status-or-only-show-hide-elements-of-choice/128662>\
**Category:** Kibana\
**Created:** [April 19, 2018, 9:26am UTC](https://discuss.elastic.co/t/refresh-the-current-status-or-only-show-hide-elements-of-choice/128662 "2018-04-19T09:26:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nikhilkvn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhilkvn/32/85872_2.png) [@nikhilkvn](https://discuss.elastic.co/u/nikhilkvn)\
**Post date:** [April 19, 2018, 9:26am UTC](https://discuss.elastic.co/t/refresh-the-current-status-or-only-show-hide-elements-of-choice/128662/1 "2018-04-19T09:26:01Z")

</div>

I have an index of documents which loosely translates as:

{  
"time": "2018-04-19T05:26:10.000Z",  
"status": "alive",  
"mac": "a1:b1:c1:d1:e1:f1",  
},

{  
"time": "2018-04-19T05:26:10.000Z",  
"status": "dead",  
"mac": "aa:bb:cc:dd:ee:ff",  
},

{  
"time": "2018-04-19T05:25:10.000Z",  
"status": "dead",  
"mac": "11:22:33:44:55:66",  
},

{  
"time": "2018-04-19T05:24:10.000Z",  
"status": "alive",  
"mac": "aa:bb:cc:dd:ee:ff",  
},  
{  
"time": "2018-04-19T05:23:10.000Z",  
"status": "alive",  
"mac": "11:22:33:44:55:66",  
},

REQ: Am trying to generate a PIE chat which lists out the MAC's only alive current moment in time.  
Problem: Getting all the MAC's which were connected historically and are now dead (dead MAC's should not been seen anymore in the viz.)  
Is there anyway i can achieve this? or should the log data itself needs to be changed. Please suggest.

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [April 19, 2018, 6:29pm UTC](https://discuss.elastic.co/t/refresh-the-current-status-or-only-show-hide-elements-of-choice/128662/2 "2018-04-19T18:29:54Z")

</div>

Couple things that work well for this are using a `Top Hit` metric, or using time series visual builder, which also shows things from the last time bucket.

Unfortunately we don't have pie charts for tsvb visualizations, and I can't seem to get this to work with our current pie charts, but if you are open to a different format you might be able to achieve this.

Here is the test data I'm working with:

 ![22%20PM](https://us1.discourse-cdn.com/elastic/original/3X/f/a/fa680c99725072749ed8b762ae7f521ffbb6a6c0.png)

Here is the incorrect pie chart because it's showing values from all time:

 ![45%20PM](https://us1.discourse-cdn.com/elastic/original/3X/4/4/44b78af10f70387d9e08136e7b141fa533e925c6.png)

Here is a top n tsvb vis that only shows the latest counts, which i think is what you want:

 ![30%20PM](https://us1.discourse-cdn.com/elastic/original/3X/c/f/cf6c21c604a52c65ff86c29a7e9074348cdb8ad2.png)

Here is a data table showing the last status:

 ![18%20PM](https://us1.discourse-cdn.com/elastic/original/3X/7/8/78230cf25b27f00fa287c5515e2d3dd4fe68e7da.png)

Hopefully this helps get you closer to your goal, if not the best answer!

---

<div class="post-metadata">

**Author:** ![nikhilkvn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhilkvn/32/85872_2.png) [@nikhilkvn](https://discuss.elastic.co/u/nikhilkvn)\
**Post date:** [April 20, 2018, 3:15am UTC](https://discuss.elastic.co/t/refresh-the-current-status-or-only-show-hide-elements-of-choice/128662/3 "2018-04-20T03:15:44Z")

</div>

Hi,

Thanks for the time and insights. I will work further in this strategy  
But, the requirement is not to show dead connections..

ONLY show the currently alive connections. (things which connected in past and are dead NOW don't make a sense)

I'm trying to show a list of CURRENTLY alive connections/devices in a particular timeframe.  
please suggest further.

---

<div class="post-metadata">

**Author:** ![nikhilkvn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhilkvn/32/85872_2.png) [@nikhilkvn](https://discuss.elastic.co/u/nikhilkvn)\
**Post date:** [April 22, 2018, 5:02pm UTC](https://discuss.elastic.co/t/refresh-the-current-status-or-only-show-hide-elements-of-choice/128662/4 "2018-04-22T17:02:01Z")

</div>

If not through visualization. is there a way i can get the list of alive connections currently through a DSL query.

List only the currently alive connections (when ever i fire the query) please help.

---

<div class="post-metadata">

**Author:** ![nikhilkvn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhilkvn/32/85872_2.png) [@nikhilkvn](https://discuss.elastic.co/u/nikhilkvn)\
**Post date:** [April 27, 2018, 4:47am UTC](https://discuss.elastic.co/t/refresh-the-current-status-or-only-show-hide-elements-of-choice/128662/5 "2018-04-27T04:47:05Z")

</div>

got the solution, with the help of this question.

> <https://stackoverflow.com/questions/39997756/elasticsearch-filtering-on-aggrigation-top-hits>

Now i have all the info. i need. is there a way i can visualize this info ? I need only the keys and show them in a pie chart.

my resultset data:

"buckets": [  
{  
"key": "00:ec:0a:8e:2e:df",  
"doc\_count": 159,  
"discon\_filter": {  
"doc\_count": 14,  
"latest\_timestamp": {  
"value": 1524056623000,  
"value\_as\_string": "2018-04-18T13:03:43.000Z"  
}  
},  
"con\_filter": {  
"doc\_count": 14,  
"latest\_timestamp": {  
"value": 1524113564000,  
"value\_as\_string": "2018-04-19T04:52:44.000Z"  
}  
}  
},  
{  
"key": "ac:5a:14:bd:4f:d1",  
"doc\_count": 156,  
"discon\_filter": {  
"doc\_count": 6,  
"latest\_timestamp": {  
"value": 1524055259000,  
"value\_as\_string": "2018-04-18T12:40:59.000Z"  
}  
},  
"con\_filter": {  
"doc\_count": 9,  
"latest\_timestamp": {  
"value": 1524114329000,  
"value\_as\_string": "2018-04-19T05:05:29.000Z"  
}  
}  
},  
{  
"key": "30:f7:72:28:f0:d5",  
"doc\_count": 134,  
"discon\_filter": {  
"doc\_count": 5,  
"latest\_timestamp": {  
"value": 1523356120000,  
"value\_as\_string": "2018-04-10T10:28:40.000Z"  
}  
},  
"con\_filter": {  
"doc\_count": 7,  
"latest\_timestamp": {  
"value": 1524115566000,  
"value\_as\_string": "2018-04-19T05:26:06.000Z"  
}  
}  
}

```
      }
    }
  ]
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2018, 4:47am UTC](https://discuss.elastic.co/t/refresh-the-current-status-or-only-show-hide-elements-of-choice/128662/6 "2018-05-25T04:47:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
