# Statisticals problem

**URL:** <https://discuss.elastic.co/t/statisticals-problem/83000>\
**Category:** Kibana\
**Created:** [April 20, 2017, 7:39am UTC](https://discuss.elastic.co/t/statisticals-problem/83000 "2017-04-20T07:39:29Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sam67000](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Post date:** [April 20, 2017, 7:39am UTC](https://discuss.elastic.co/t/statisticals-problem/83000/1 "2017-04-20T07:39:29Z")

</div>

Hello EveryOne,

I need your help.  
I work on logs telephony and I would like to do statistics with kibana to know the percentage of successful call.

When a call is passed, this line appears :

 ![](https://us1.discourse-cdn.com/elastic/original/3X/6/8/68d443fb01ff31c50403d84fca338fe1921a30a0.png)

And when a call doesn't pass, this line appears :

 ![](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4aab2179ebb382f5b892cde86008d7ee36b7a63e.png)

For now I managed to extract all the lines of past calls and put them in a variable. Same for unanswered calls.  
But now I don't know how to make statistics.

Please help, THannnks !

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 20, 2017, 7:47am UTC](https://discuss.elastic.co/t/statisticals-problem/83000/2 "2017-04-20T07:47:54Z")

</div>

Please don't post pictures of text, they are difficult to read and some people may not be even able to see them.

---

<div class="post-metadata">

**Author:** ![Sam67000](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Post date:** [April 20, 2017, 7:51am UTC](https://discuss.elastic.co/t/statisticals-problem/83000/3 "2017-04-20T07:51:04Z")

</div>

When a call is passed, this line appears :

2017-04-13T10:32:02.546 Int 22000 ##### EI\_COF\_SICRC04\_DistriSortant\_STR-v1 - 0071029d90c9b5bf - Appel Campagne : C\_PREREC\_GLOBAL@AG\_PREREC\_GLOB Appel : 972826533 Chain ID : 175079311 **Ditribution : OK**

And when a call doesn't pass, this line appears :

2017-04-13T10:32:16.055 Int 22000 ##### EI\_COF\_SICRC04\_DistriSortant\_STR-v1 - 0071029d90c9b643 - Appel Campagne : C\_PREREC\_GLOBAL@AG\_PREREC\_GLOB Appel : 617595782 Chain ID : 166259911 **Ditribution : KO**

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 20, 2017, 7:53am UTC](https://discuss.elastic.co/t/statisticals-problem/83000/4 "2017-04-20T07:53:42Z")

</div>

What do the records in Elasticsearch look like? Which fields have you parsed out?

---

<div class="post-metadata">

**Author:** ![Sam67000](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Post date:** [April 20, 2017, 8:13am UTC](https://discuss.elastic.co/t/statisticals-problem/83000/5 "2017-04-20T08:13:15Z")

</div>

I'm working on logs that looks like this :

 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/1/011b8029160902db78ff3a30d30d7fbdd86a2ce8.png)

I use a multiline filter that parses the documents on each new date.

Then I use a grok filter that stores only the lines that indicate whether the call is OK or KO and which stores them in two variables DAS1 and DAS2.

Here is an example :

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8dd0a82eb52d7a523f59128bc20a98e6ff36c6c1.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 20, 2017, 8:25am UTC](https://discuss.elastic.co/t/statisticals-problem/83000/6 "2017-04-20T08:25:19Z")

</div>

As Mark mentioned earlier, please do not post images of text. In order to easily analyse this in Cabana, you need to extract the relevant parts of the log message in Logstash. If you e.g. parsed out the `OK`/`KO` status into a field called `call_status` you would be able to build visualisations and dashboards around this.

I would therefore recommend you perform a bit more parsing of your log messages in Logstash.

---

<div class="post-metadata">

**Author:** ![Sam67000](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Post date:** [April 20, 2017, 8:34am UTC](https://discuss.elastic.co/t/statisticals-problem/83000/7 "2017-04-20T08:34:10Z")

</div>

Ok. Soory. This is a part of the log :

**2017-04-13T10:31:59.691** Int 22000 ##### EI\_COF\_SICRC04\_DistriSortant\_STR-v1 - 0071029d90c9b5bd - Appel Campagne : C\_F300@AG\_F300 Appel : 648666576 Chain ID : 140197011 Ditribution : **OK**  
\_I\_I\_0071029d90c9b5bd [09:04] OP\_XCALL\_NO\_RESULT: func Exit returns INTERP\_STOP(0), go to stop handling  
\_I\_I\_0071029d90c9b5bd [01:0a] \<\<\<\<\<\<\<\<\<\<\<\<stop interp  
**2017-04-13T10:31:59.691** \_M\_I\_0071029d90c9b5bd [10:2f] RStatCallsInQueue update: object \<21097\>(3908), type CfgDN value 0+0+0, reason   
**2017-04-13T10:31:59.691** \_M\_I\_0071029d90c9b5bd [10:2f] RStatCallsInQueue update: object \<1223\_CO11740\>(1617), type CfgPerson value 0+0+0, reason   
**2017-04-13T10:31:59.691** \_M\_I\_0071029d90c9b5bd [10:2f] RStatCallsInQueue update: object \<Place\_ES\_21097\>(1145), type CfgPlace value 0+0+0, reason   
**2017-04-13T10:31:59.691** \_I\_I\_0071029d90c9b5bd [01:08] call (4267125-0000000006ffb890) deleting truly  
**2017-04-13T10:31:57.195** Int 22000 ##### EI\_COF\_SICRC04\_DistriSortant\_STR-v1 - 0071029d90c9b5c0 - Appel Campagne : C\_PREREC\_GLOBAL@AG\_PREREC\_GLOB Appel : 972825082 Chain ID : 174568111 Ditribution : **OK**  
\_I\_I\_0071029d90c9b5c0 [09:04] OP\_XCALL\_NO\_RESULT: func Exit returns INTERP\_STOP(0), go to stop handling  
\_I\_I\_0071029d90c9b5c0 [01:0a] \<\<\<\<\<\<\<\<\<\<\<\<stop interp  
**2017-04-13T10:31:57.195** \_M\_I\_0071029d90c9b5c0 [10:2f] RStatCallsInQueue update: object \<1760\_CO05077\>(827), type CfgPerson value 0+0+0, reason \<no cal

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 20, 2017, 10:23am UTC](https://discuss.elastic.co/t/statisticals-problem/83000/8 "2017-04-20T10:23:19Z")

</div>

You will need to define parsing of these events in your Logstash config, e.g. by using a grok filter, so you may want to continue the discussion and follow Magnus' advice in the topic you have open under the Logstash category.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2017, 10:37am UTC](https://discuss.elastic.co/t/statisticals-problem/83000/9 "2017-05-18T10:37:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
