# Timelion counting dates for rows

**URL:** <https://discuss.elastic.co/t/timelion-counting-dates-for-rows/122153>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [March 1, 2018, 9:06pm UTC](https://discuss.elastic.co/t/timelion-counting-dates-for-rows/122153 "2018-03-01T21:06:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![rhass](https://avatars.discourse-cdn.com/v4/letter/r/b5a626/32.png) [@rhass](https://discuss.elastic.co/u/rhass)\
**Post date:** [March 1, 2018, 9:06pm UTC](https://discuss.elastic.co/t/timelion-counting-dates-for-rows/122153/1 "2018-03-01T21:06:08Z")

</div>

Hello!

I am using timelion and I am having an issue with the display. It seems that timelion is doing a count of all rows that hit on a certain date and is displaying that. For example. I have the "date" field below. Instead of the date displaying the gestures seen on jan1 of hellos I get the date showing there is one row in 1jan.

I need timelion to show me 1jan with 57 counts and 2jan with 31 counts. I hope this makes sense.

Date| gesture | counts of gestures  
1jan| hello | 57  
2jan| hello | 31  
3jan| hello | 21

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [March 4, 2018, 1:06am UTC](https://discuss.elastic.co/t/timelion-counting-dates-for-rows/122153/2 "2018-03-04T01:06:07Z")

</div>

The default metric aggregation for each time bucket in the histogram is `count`, so you get a count of the documents that were bucketed for each date.

There are other metric aggregations to choose from. The `metric` parameter to the `.es()` function has help text that talks about it:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/3/b3a96b23baae4324a2e7a793c8e769cb972e8332.png)

I think you are looking for something like: `.es(index=mydata-*, metric=sum:counts_of_gestures, split=gesture)`

---

<div class="post-metadata">

**Author:** ![rhass](https://avatars.discourse-cdn.com/v4/letter/r/b5a626/32.png) [@rhass](https://discuss.elastic.co/u/rhass)\
**Post date:** [March 5, 2018, 8:13pm UTC](https://discuss.elastic.co/t/timelion-counting-dates-for-rows/122153/3 "2018-03-05T20:13:26Z")

</div>

Thank you for the reply! I was able to change the split=date and that is correct. However, when I tried:  
split=gesture:1000 (it asked for field:limit)  
I get the error that "fielddata is disabled on text fields".  
I did some searching and found that I need to edit in my mapping but am having difficult with the syntax I believe.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [March 6, 2018, 12:21am UTC](https://discuss.elastic.co/t/timelion-counting-dates-for-rows/122153/4 "2018-03-06T00:21:56Z")

</div>

Check to see if your `gesture` field is possibly a multi-field. If so, then whenever you reference the data as `gesture`, it will use the part of the multi-field that is mapped as text. If you have a `gesture.raw` field, that is the part of the multi-field that is non-analyzed text (mapped as `keyword`) and you can use that for a field to aggregate on.

Most of the ingestion tools default to mapping text data as a multi-field with analyzed text and the non-analyzed keyword that I described. Documentation: [https://www.elastic.co/guide/en/elasticsearch/reference/6.2/multi-fields.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/multi-fields.html)

If the text data is not a multi-field, or you don't have any other fields that represent the non-analyzed version of the gesture, then you'll need to come up with a custom mapping and re-index the data into an index that has the working mapping.

---

<div class="post-metadata">

**Author:** ![rhass](https://avatars.discourse-cdn.com/v4/letter/r/b5a626/32.png) [@rhass](https://discuss.elastic.co/u/rhass)\
**Post date:** [March 6, 2018, 2:02pm UTC](https://discuss.elastic.co/t/timelion-counting-dates-for-rows/122153/5 "2018-03-06T14:02:51Z")

</div>

I changed it from split=gesture:10 to split=gesture.keyword:10 and that worked.

I appreciate the guidance it has helped me out a lot. Thank you!!

---

<div class="post-metadata">

**Author:** ![rhass](https://avatars.discourse-cdn.com/v4/letter/r/b5a626/32.png) [@rhass](https://discuss.elastic.co/u/rhass)\
**Post date:** [March 15, 2018, 7:04pm UTC](https://discuss.elastic.co/t/timelion-counting-dates-for-rows/122153/6 "2018-03-15T19:04:43Z")

</div>

Tim,

I would like to pull out and only see the "hi gesture" and filter those based on the days. so how would i construct the query to show me "hi" for both jan and february?

Date| gesture | counts of gestures  
1jan| hello | 57  
2jan| hello | 31  
3jan| hello | 21  
3jan| hi | 39  
4jan| hi | 17  
5jan| wave | 3  
6jan|wave | 20  
1feb| hello | 57  
2feb| hello | 31  
3feb| hello | 21  
3feb| hi | 39  
4feb| hi | 17  
5feb| wave | 3  
6feb|wave | 20

Also, do you offer official timelion training like the other Elastic courses?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [March 20, 2018, 1:50am UTC](https://discuss.elastic.co/t/timelion-counting-dates-for-rows/122153/7 "2018-03-20T01:50:35Z")

</div>

Hi,

You can use the `q` parameter in the `.es` function add a query that will filter for the `hi` gesture:

```auto
.es(index=mydata-*, metric=sum:counts_of_gestures, split=gesture.keyword:10, q="gesture.keyword:hi")

```

The `q` parameter can do any kind of Lucene query to filter the data. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2018, 1:51am UTC](https://discuss.elastic.co/t/timelion-counting-dates-for-rows/122153/8 "2018-04-17T01:51:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
