# Subtracting one value out of another and showing the percentage difference

**URL:** <https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926>\
**Category:** Kibana\
**Created:** [December 8, 2023, 4:37pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926 "2023-12-08T16:37:17Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dor-Alter](https://avatars.discourse-cdn.com/v4/letter/d/7ea924/32.png) [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Post date:** [December 8, 2023, 4:37pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/1 "2023-12-08T16:37:17Z")

</div>

I am trying to get a pie dashboard of successful vs abendent processes out of my logs.

My issue is that there is no way to filter the abendent processes.  
So what I can do is filter based on the values that are successful and based on the total ones.

As it is logs they are no one entry, so I filter based on the logs of process start and process successful.

What I get is a pie that has the total vs the successful and what I want to do is make a formula that will give me the percentage of successful over the total - successful.

How can I do that using formula?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 8, 2023, 4:56pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/2 "2023-12-08T16:56:27Z")

</div>

What version?  
What Visualization? Lens?

> [@Dor-Alter](#):
>
> My issue is that there is no way to filter the abendent processes.

Not quite clear...  
Can you provide some samples / of your data and what you calculations are?

Perhaps You could use a runtime field to mark which ones are successful.

---

<div class="post-metadata">

**Author:** ![Dor-Alter](https://avatars.discourse-cdn.com/v4/letter/d/7ea924/32.png) [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Post date:** [December 8, 2023, 5:25pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/3 "2023-12-08T17:25:40Z")

</div>

This is only part of them but as an example:

```auto
"log_id": "1234566788ab214",
"policy_id": "registration",
"time_lo_res": "1697182080000",
"@timestamp": "2023-10-13T07:28:27.545Z",
"action": “login_start”,
"session_id": "af443e6410c2",
"time": "1697182107545"
          
"log_id": "1234566788ab217”,
"policy_id": "registration",
"time_lo_res": "1697182080000",
"@timestamp": "2023-10-13T07:28:27.545Z",
"session_id": "af443e6410c2",
"action": “login_successful”,
"time": "1697182107745"
          
"log_id": "1234566788ab227”,
"policy_id": "registration",
"time_lo_res": "1697182080000",
"@timestamp": "2023-10-13T07:28:27.545Z",
"action": “login_start”,
"session_id": "af443e6410c2",
"time": "1697182108545"

"log_id": "1234566788ab427”,
"policy_id": "registration",
"time_lo_res": "1697182080000",
"@timestamp": "2023-10-13T07:29:27.545Z",
"action": “login_start”,
"session_id": "af443ee41ac2",
"time": "1697182108575"

```

Now in this case you can see that there are three login\_start and one login\_successful and I want to create a dashboard that will show me 1 successful and 2 abendent.

To filter those logs from all logs I use the action = login\_start or action = login\_successful filter but then I still need to use some formula to get the right values. There are no other attributes in the logs that I can use to make the distinction.

I am using version 8.11 and using Pie but Donut will also be fine.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 8, 2023, 5:34pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/4 "2023-12-08T17:34:32Z")

</div>

> [@Dor-Alter](#):
>
> but then I still need to use some formula to get the right values.

Can you provide the actual calculation using the exampless above?

How are you identifying abedent? A start without a successful?

I am thinking you could leverage a lastest transform on the data as these data need to be correlated on `session_id`

> **[Transform overview | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/transform-overview.html#latest-transform-overview)**

This will just keep the latest state based on log\_id and then the calculations are probably easier

---

<div class="post-metadata">

**Author:** ![Dor-Alter](https://avatars.discourse-cdn.com/v4/letter/d/7ea924/32.png) [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Post date:** [December 8, 2023, 5:44pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/5 "2023-12-08T17:44:58Z")

</div>

Yes it is just start without a successful.

There are more logs in between the login\_start and login\_successful but for simplicity I only included those.

The data is already in elastic but now I want to generate a dashboard out of it. And it is not really user specific because before the user logs in there is no id and then the id changes. The session\_id is just a number that increases based on the logs.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 8, 2023, 5:50pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/6 "2023-12-08T17:50:42Z")

</div>

I highly recommend looking at the latest transform it is basically fit for purpose for your use cases. There is a UI builder in Kibana to create the transform

Kibana - Stack Management - Transforms

Otherwise you will struggle to do the analysis you're trying to do

Perhaps the `session_id` is the correlation...

---

<div class="post-metadata">

**Author:** ![Dor-Alter](https://avatars.discourse-cdn.com/v4/letter/d/7ea924/32.png) [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Post date:** [December 8, 2023, 5:54pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/7 "2023-12-08T17:54:13Z")

</div>

My bad I do have a correlation it seems like I did not include it in my example. There is group\_id that makes the correlation between the start log and successful log.

It is such that if the logs relate to one session they will all have the same value for group\_id.

And I noticed that I can use the unique\_count(group\_id) to make sure I do not have duplicates but for now I get a pie that shows all logins vs successful ones while I want to get (total - successful) vs successful

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 8, 2023, 6:27pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/8 "2023-12-08T18:27:32Z")

</div>

Perhaps You can use KQL filter in that unique\_count one with a filter `"action": “login_successful”` and one without a filter

What is your definition of total?

Keep working on the formula....

The latest transform would probably make this all easier

---

<div class="post-metadata">

**Author:** ![Dor-Alter](https://avatars.discourse-cdn.com/v4/letter/d/7ea924/32.png) [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Post date:** [December 8, 2023, 6:36pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/9 "2023-12-08T18:36:34Z")

</div>

My issue is that when I do minus it will remove all the entries of successful

If I try something like:

```auto
unique_count(group_id) - unique_count(group_id, kql='action :"login_seccessful"') 

```

I would like to somehow only subtract the count from the other case.

For the other case we can use the kql='action :"login\_start"'.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 8, 2023, 7:18pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/10 "2023-12-08T19:18:22Z")

</div>

> [@Dor-Alter](#):
>
> `action :"login_seccessful"`

typo

> [@Dor-Alter](#):
>
> I would like to somehow only subtract the count from the other case.

I do not know what that means you can do `not` logic

`kql='not action :"login_successful"'`

You can figure it out... I will say one last time the Latest Transform would probably take 5 mins to setup then you would have "processed / correlated" data to work with.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 5, 2024, 7:18pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926/11 "2024-01-05T19:18:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
