# TimeLion basic question

**URL:** https://discuss.elastic.co/t/timelion-basic-question/70309
**Category:** Kibana
**Tags:** timelion
**Created:** [December 31, 2016, 2:58am UTC](https://discuss.elastic.co/t/timelion-basic-question/70309 "2016-12-31T02:58:09Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![queenstownswords](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/queenstownswords/32/49399_2.png) [@queenstownswords](https://discuss.elastic.co/u/queenstownswords)
#### Post date: [December 31, 2016, 2:58am UTC](https://discuss.elastic.co/t/timelion-basic-question/70309/1 "2016-12-31T02:58:09Z")

</div>

Hello,

Please excuse, there is not a timelion category yet.

I am new to elasticsearch/kibana so thanks for your patience.  
There is an index 'testindexname' with entries in the following format:  
{"\_index":"testindexname","\_type":"datecount","\_id":"201612022249","\_version":1,"found":true,"\_source":{ "clientId" : "1", "date" : "2016-12-02", "count" : 37857.0 }}

I can see the visualisations fine in kibana's 'visualize' and 'dashboard'.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/4498228b17d340a59c43f99c9a0e9b69e18ba428.JPG)

However, es(\*) only gives a value of 0 for the timeline.  
The following es() arguments have been tried without change:

- es(index='testindexname')
- es(metric='sum:count')
- es(q=clientId:1)
- and a combination of the parameters.

Changing the date window (tried 5y, 2y, 1y, 30d, etc.) does not help.

What am I missing?

Note: for an end result, I would like to index multiple client ids (1, 2, ...) and graph in timelion a line for each graph.  
I do not know if it is cleaner to put each client id in a separate index or to use one index for multiple client ids.

Thanks for your time.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [January 1, 2017, 2:46am UTC](https://discuss.elastic.co/t/timelion-basic-question/70309/2 "2017-01-01T02:46:33Z")

</div>

You need to set your `timefield`.

---

<div class="post-metadata">

### Author: ![queenstownswords](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/queenstownswords/32/49399_2.png) [@queenstownswords](https://discuss.elastic.co/u/queenstownswords)
#### Post date: [January 3, 2017, 6:39am UTC](https://discuss.elastic.co/t/timelion-basic-question/70309/3 "2017-01-03T06:39:46Z")

</div>

@warkolm Many thanks. That got it.

If there is any insight as to why it would be 'date' instead of '@date' that would also be helpful- or any other resource as google/youtube are only somewhat helpful.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [January 3, 2017, 7:26am UTC](https://discuss.elastic.co/t/timelion-basic-question/70309/4 "2017-01-03T07:26:03Z")

</div>

Because that is what you passed to ES.

`@`-prefixed fields are used by Logstash, but they aren't reserved.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 31, 2017, 7:26am UTC](https://discuss.elastic.co/t/timelion-basic-question/70309/5 "2017-01-31T07:26:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
