# Suggestions for presenting data

**URL:** <https://discuss.elastic.co/t/suggestions-for-presenting-data/67883>\
**Category:** Kibana\
**Created:** [December 2, 2016, 4:41pm UTC](https://discuss.elastic.co/t/suggestions-for-presenting-data/67883 "2016-12-02T16:41:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cylindric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cylindric/32/5660_2.png) [@Cylindric](https://discuss.elastic.co/u/Cylindric)\
**Post date:** [December 2, 2016, 4:41pm UTC](https://discuss.elastic.co/t/suggestions-for-presenting-data/67883/1 "2016-12-02T16:41:20Z")

</div>

I posted a question recently about [cross-tabulation of data](https://discuss.elastic.co/t/tabulating-data-based-on-a-field), and I thought rather than try and create what is in my head, I'd see if anyone can suggest a different way of presenting the data I need.

So I have a bunch of documents representing messages being sent. Each record has a destination address, and a status to say whether it sent or not.

```
2016-12-02 01:00:00 alice@a.com success
2016-12-02 01:00:00 bob@b.com success
2016-12-02 01:00:00 charles@c.com fail
2016-12-02 02:00:00 alice@a.com fail
2016-12-02 02:00:00 bob@a.com success
2016-12-02 02:00:00 charles@a.com fail

```

And what I currently report is a summary of destinations, and how successful sends are:

```
address sent success%
--------------------------
alice@a.com 2 50%
bob@b.com 2 100%
charles@c.com 2 0%

```

I don't seem to be able to create such a visualisation in Kibana, so I was wondering if someone else had any suggestions.

The key bit to report on is which ones have the worst success rate, regardless of the total number sent, so some way of showing the "Top 20 Bad Addresses" would probably do.

Thanks

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [December 3, 2016, 3:00am UTC](https://discuss.elastic.co/t/suggestions-for-presenting-data/67883/2 "2016-12-03T03:00:18Z")

</div>

I don't think you will be able to render a table that shows the percentage of requests that failed for a specific user. You get that in a chart by splitting on username and then status and rendering it in a percentage style, but probably won't be super useful.

I would probably start with something like this:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/7/7c4f4188211ca1f8d0f990a44cebca88e2d862ad.gif)

A dashboard that shows the percentage of failed/successful messages, the total number of messages, and the total number of failed messages for the top failure destinations.

By putting these together on a dashboard you can spot when an abnormal amount of failures occur, spot which destinations are most affected, and click on any of those destinations to drill down and see their specific breakdown.

Does that help?

saved objects:

- index pattern
  - messages, `time` as timefield

- search
  - failed messages, query: `status:fail`

- visualizations
  - top failure destinations, based on "failed messages" search, `terms` agg on `to` field
  - Success vs Failure, area chart based on "messages" index pattern, `date_histogram` on `time` and split area by `status`
  - Total Messages, metric vis based on "messages" index pattern, `count` of all documents

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2016, 3:00am UTC](https://discuss.elastic.co/t/suggestions-for-presenting-data/67883/3 "2016-12-31T03:00:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
