# Time Filter behaving strangely

**URL:** <https://discuss.elastic.co/t/time-filter-behaving-strangely/214680>\
**Category:** Kibana\
**Created:** [January 10, 2020, 10:38pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680 "2020-01-10T22:38:51Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![sidhusaab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidhusaab/32/60034_2.png) [@sidhusaab](https://discuss.elastic.co/u/sidhusaab)\
**Post date:** [January 10, 2020, 10:38pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/1 "2020-01-10T22:38:51Z")

</div>

I have an index which contains data for the last 3 days (Jan 08 - Jan 10). I have a dashboard that shows different things from the index and it seems to only work if my time range is set to 7 days or more. If I set last 24 hours, last hour etc the charts do not show any data.

I have attached the gif that shows this behavior. I am clueless on the cause and require help or suggestions on what could this be.

 ![elk_time](https://us1.discourse-cdn.com/elastic/original/3X/1/3/13cffb89a16798832b475e77cb2309fec00dda9d.gif)

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [January 13, 2020, 8:34am UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/2 "2020-01-13T08:34:01Z")

</div>

Hi @sidhusaab,

Could you [press the inspect button](https://www.elastic.co/guide/en/kibana/current/vis-inspector.html) for the problematic visualizations and post the request and response made here? Additionally the JSON of the exported visualization would be helpful to see what exactly is going wrong.

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [January 13, 2020, 11:57am UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/3 "2020-01-13T11:57:46Z")

</div>

Hi there,

is it possible that for that TSVB visualization you have the `interval` setting under `Panel Option` set to a static value greater than 24h?

If you set it to 3d and then tries to visualize the last 15 minutes you won't see anything.

If that's the case, try setting it to `auto` or leave it blank.

---

<div class="post-metadata">

**Author:** ![sidhusaab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidhusaab/32/60034_2.png) [@sidhusaab](https://discuss.elastic.co/u/sidhusaab)\
**Post date:** [January 13, 2020, 3:40pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/4 "2020-01-13T15:40:16Z")

</div>

@flash1293 I am using Timelion type visualization and Inspect button is greyed out for me.

@Fabio-sama Its set to auto in the interval settings.

---

<div class="post-metadata">

**Author:** ![sidhusaab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidhusaab/32/60034_2.png) [@sidhusaab](https://discuss.elastic.co/u/sidhusaab)\
**Post date:** [January 13, 2020, 3:55pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/5 "2020-01-13T15:55:20Z")

</div>

Interestingly, following along the Fabio's suggestion I set the interval to 10m and it worked for Last 24 hours, Last 30 mins etc now but the graphs aren't as pretty. So for now, I'll stick to setting a static value but would like to know why when `interval=auto` it does not work.

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [January 13, 2020, 4:36pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/6 "2020-01-13T16:36:46Z")

</div>

Oh you are using Timelion. You know, I remember having a very similar problem with timelion some months (and versions) ago (together with a small graphic bug using the dark theme) and that was one of the reasons why I switched to TSVB.

Why not using this last one?

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [January 13, 2020, 4:38pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/7 "2020-01-13T16:38:44Z")

</div>

Also because setting such a small interval it'd become impossible to plot a 3-month graph, for computing and ease of reading reasons.

---

<div class="post-metadata">

**Author:** ![sidhusaab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidhusaab/32/60034_2.png) [@sidhusaab](https://discuss.elastic.co/u/sidhusaab)\
**Post date:** [January 13, 2020, 4:58pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/8 "2020-01-13T16:58:13Z")

</div>

The only reason I am using Timelion vs TSVB is because I have 6 metrics in one graph that I want to monitor and since their values are above zero, it would (IMO) made the graph look messy. So I converted some of the bad metrics into negative values (multiply -1) and they looked better. If I can do something similar in TSVB, I will switch them over.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [January 13, 2020, 5:34pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/9 "2020-01-13T17:34:28Z")

</div>

Ah I didn’t realize these were timelion visualizations. In this case the problem is that the frequency of your data is too low for the auto interval and there are empty buckets between buckets that contain data. In the default setting timelion doesn’t show a chart in this case. You can fix this by using the “fit” function as described here: [Displaying sparse data in Timelion using fit()](https://discuss.elastic.co/t/displaying-sparse-data-in-timelion-using-fit/118386/3) this will interpolate the empty buckets and still show a chart (without having the problem of creating too many buckets with large date ranges)

---

<div class="post-metadata">

**Author:** ![sidhusaab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidhusaab/32/60034_2.png) [@sidhusaab](https://discuss.elastic.co/u/sidhusaab)\
**Post date:** [January 13, 2020, 6:55pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/10 "2020-01-13T18:55:47Z")

</div>

Ok so I added .fit(none) and changed interval to auto. Back to the same problem.

For context, the data is pulled by http\_poller plugin every 10 minutes and I verified that the data is available in the index.

For example: The last 3 hours look like this

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/b/cb387e28093e94465c6e0bac24cb550ee9548a85.png)

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [January 13, 2020, 7:15pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/11 "2020-01-13T19:15:41Z")

</div>

Could you try something else than none, e.g. “carry”

---

<div class="post-metadata">

**Author:** ![sidhusaab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidhusaab/32/60034_2.png) [@sidhusaab](https://discuss.elastic.co/u/sidhusaab)\
**Post date:** [January 13, 2020, 8:42pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/12 "2020-01-13T20:42:25Z")

</div>

Interval set to auto, Time range: last 1 hour, fit(carry) - empty graph.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [January 13, 2020, 9:14pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/13 "2020-01-13T21:14:30Z")

</div>

Could you share your complete timelion script? That will help pin-pointing the problem here. As a side node - moving some series into the negative area of the y axis by multiplying with “-1” should also be possible in tsvb using the “math” aggregation (like here:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/5/05581c78836fddc6450e07597c80b1ee57243a3b.png)

---

<div class="post-metadata">

**Author:** ![sidhusaab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidhusaab/32/60034_2.png) [@sidhusaab](https://discuss.elastic.co/u/sidhusaab)\
**Post date:** [January 13, 2020, 9:21pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/14 "2020-01-13T21:21:12Z")

</div>

Thank you for sticking with me this far. Greatly appreciated.

In this example, I am plotting the 6 record types.

```auto
.es(index=bindjson*,timefield='@timestamp', metric=max:qtypes.A).derivative().label("A").lines(fill=2,width=1).color(#03f4fc).fit(carry),
.es(index=bindjson*,timefield='@timestamp', metric=max:types.AAAA).derivative().label("AAAA").multiply(-1).lines(fill=2,width=1).color(#b503fc).fit(carry), 
.es(index=bindjson*,timefield='@timestamp', metric=max:types.CNAME).derivative().label("CNAME").multiply(-1).lines(fill=1,width=1).color(#03dffc).fit(carry), 
.es(index=bindjson*,timefield='@timestamp', metric=max:types.TXT).derivative().label("TXT").lines(fill=2,width=1).color(#84fc03).fit(carry), 
.es(index=bindjson*,timefield='@timestamp', metric=max:types.SOA).derivative().label("SOA").lines(fill=3,width=1).color(#fcba03).fit(carry),
.es(index=bindjson*,timefield='@timestamp', metric=max:qtypes.SRV).derivative().label("SRV").multiply(-1).lines(fill=2,width=1).color(#03fc9d).fit(carry), 
.es(index=bindjson*,timefield='@timestamp', metric=max:types.NS).derivative().label("NS").multiply(-1).lines(fill=1,width=1).color(#dbfc03).fit(carry)
```

---

<div class="post-metadata">

**Author:** ![sidhusaab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidhusaab/32/60034_2.png) [@sidhusaab](https://discuss.elastic.co/u/sidhusaab)\
**Post date:** [January 13, 2020, 9:38pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/15 "2020-01-13T21:38:02Z")

</div>

So as you are looking into it, I think the problem comes from `derivative`. If I remove it then I can see the graphs.

Now, why i used derivative is because the source of data keeps counters from start time and does not reset them until the process restarts. So, hence my use of derivative. Am i using that incorrectly or is there an alternative to derivative? Basically what I want to see is the delta since the last time. It will either be '0' or a positive number unless the process restarts and resets the counters to zero.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [January 14, 2020, 2:50pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/16 "2020-01-14T14:50:56Z")

</div>

You are right, `derivative` is causing your problem. This is the underlying code:

```auto
      eachSeries.data = _.map(pairs, function(point, i) {
        if (i === 0 || pairs[i - 1][1] == null || point[1] == null) {
          return [point[0], null];
        }
        return [point[0], point[1] - pairs[i - 1][1]];
      });

```

It will output the difference to the data point before the current data point, but won't skip null values.

Could you try applying `fit` before `derivative`? Then it should fill in the missing values before calculating the derivative, which should give you the derivative of the existing values. In this case `fit(none)` should be the right choice because it basically just gets rid of the null data points in between.

```auto
.es(index=bindjson*,timefield='@timestamp', metric=max:qtypes.A).fit(none).derivative().label("A").lines(fill=2,width=1).color(#03f4fc),

```

---

<div class="post-metadata">

**Author:** ![sidhusaab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sidhusaab/32/60034_2.png) [@sidhusaab](https://discuss.elastic.co/u/sidhusaab)\
**Post date:** [January 14, 2020, 3:38pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/17 "2020-01-14T15:38:39Z")

</div>

That did it!

The graphs work now. I will work on cleaning/formatting them a little but overall works for what I need.

Awesome and thank you for your help. 🙂 👍

 ![elk_time2](https://us1.discourse-cdn.com/elastic/original/3X/3/8/38819c9757eb66831847d21a15f950de6e44b7e0.gif)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2020, 3:41pm UTC](https://discuss.elastic.co/t/time-filter-behaving-strangely/214680/18 "2020-02-11T15:41:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
