# Timelion Aggregate graph with different interval/condition

**URL:** <https://discuss.elastic.co/t/timelion-aggregate-graph-with-different-interval-condition/306651>\
**Category:** Kibana\
**Created:** [June 8, 2022, 8:15am UTC](https://discuss.elastic.co/t/timelion-aggregate-graph-with-different-interval-condition/306651 "2022-06-08T08:15:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert\_Naccache](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robert_naccache/32/97656_2.png) [@Robert\_Naccache](https://discuss.elastic.co/u/Robert_Naccache)\
**Post date:** [June 8, 2022, 8:15am UTC](https://discuss.elastic.co/t/timelion-aggregate-graph-with-different-interval-condition/306651/1 "2022-06-08T08:15:40Z")

</div>

Hello,

I'm trying to create a Timelion aggregation and wondering if its possible.

Basically the case is, I have documents that includes http response codes. What i'm trying to do is:

- The default interval could be days/weeks
- Display the count of 200-299 http status, this is done using (this is ok):

```auto
.es(index=application-logs, timefield='@timestamp',q="status:[200 TO 299]").color(color=green).label(label="2xx status log count")

```

Now the part i'm stumped in is regarding the 500 errors. Regardless of the interval, what i need to figure out is how to display the total count of documents with 500 errors **IF there are more than 5 documents with 500 Status in a bucket of 30 seconds**

amongst other things, the closes i came to was after i tried using scale\_interval :

```auto
.es(index=application-logs,timefield='@timestamp',q="status:[500 TO 599]").if(operator=lt,if=5,then=null).color(color=red).points(symbol=circle,radius=5).label(label="5xx status log count over 0/30(sec)").scale_interval(30s),

```

But my issue here is that when i zoom out on a different interval (daily,weekly) i get a weird value:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9e12520f20dd46f533e00231e186e63ee84aca4a.png)

If anyone has a clue, or some sort of direction or approach i could try, I'd greatly appreciate it!

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2022, 8:15am UTC](https://discuss.elastic.co/t/timelion-aggregate-graph-with-different-interval-condition/306651/2 "2022-07-06T08:15:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
