# Simple Metric Aggregation to Determine Delta Values in Kibana

**URL:** <https://discuss.elastic.co/t/simple-metric-aggregation-to-determine-delta-values-in-kibana/50376>\
**Category:** Kibana\
**Created:** [May 18, 2016, 9:36pm UTC](https://discuss.elastic.co/t/simple-metric-aggregation-to-determine-delta-values-in-kibana/50376 "2016-05-18T21:36:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![seth.yes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seth.yes/32/11788_2.png) [@seth.yes](https://discuss.elastic.co/u/seth.yes)\
**Post date:** [May 18, 2016, 9:36pm UTC](https://discuss.elastic.co/t/simple-metric-aggregation-to-determine-delta-values-in-kibana/50376/1 "2016-05-18T21:36:27Z")

</div>

I am passing network metrics to my ELK stack. Some data is presented in counters; always incrementing the bits sent, for example. However, I need to display the rate of change in these counters over a fixed sampling period (e.g. a gauge that tells me the current bitrate).

Is there a way in Kibana to do rather-simple metric aggregation such as this? I see that scripted aggregations are possible in Elasticsearch, but from what I've read, this is not supported when using Kibana as the frontend.

If this is not feasible with Kibana, does anyone have recommendations for using another tool to determine the delta values, which can then be passed to ELK? Thanks for any help/advice.

I'm using the most-recent non-beta stack and the devices I'm monitoring don't appear to be configured (from a FW standpoint) to display gauges (delta values) in regards to these counters.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 19, 2016, 1:08pm UTC](https://discuss.elastic.co/t/simple-metric-aggregation-to-determine-delta-values-in-kibana/50376/2 "2016-05-19T13:08:23Z")

</div>

Timelion can do this for you, but native KB cannot.

---

<div class="post-metadata">

**Author:** ![seth.yes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seth.yes/32/11788_2.png) [@seth.yes](https://discuss.elastic.co/u/seth.yes)\
**Post date:** [May 19, 2016, 4:41pm UTC](https://discuss.elastic.co/t/simple-metric-aggregation-to-determine-delta-values-in-kibana/50376/3 "2016-05-19T16:41:34Z")

</div>

You're right, Timelion looks like it can produce the derivative of the data, which is what I need. However I can hardly find any documentation on installing or configuring it. I've read I just need to install it as I would Marvel, but it's disconcerting not having any real documentation on it, as I'd find with most supported plugins.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 23, 2016, 3:50am UTC](https://discuss.elastic.co/t/simple-metric-aggregation-to-determine-delta-values-in-kibana/50376/4 "2016-05-23T03:50:27Z")

</div>

It's not supported, it's still essentially an alpha.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:52pm UTC](https://discuss.elastic.co/t/simple-metric-aggregation-to-determine-delta-values-in-kibana/50376/5 "2017-07-06T13:52:39Z")

</div>


