# Timelion expression

**URL:** <https://discuss.elastic.co/t/timelion-expression/160315>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [December 11, 2018, 7:41am UTC](https://discuss.elastic.co/t/timelion-expression/160315 "2018-12-11T07:41:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![koushickvikram](https://avatars.discourse-cdn.com/v4/letter/k/4491bb/32.png) [@koushickvikram](https://discuss.elastic.co/u/koushickvikram)\
**Post date:** [December 11, 2018, 7:41am UTC](https://discuss.elastic.co/t/timelion-expression/160315/1 "2018-12-11T07:41:45Z")

</div>

\*\*

> Timelion expression required

\*\*

Hi All,  
Below is the log format in our organisation, please let me know the expression for creation of **TIMELION** which can show us the **_graph of Response code : 200_**

Thanks in advance.

**LOG:**

| @timestamp | | December 11th 2018, 13:06:36.000 |
| --- | --- | --- |
| t \_id | | xxxxxxxxxxxx |
| t \_index | | xxxxxxxxxxxx |
| # \_score | | - |
| t \_type | | nginx-logs |
| t agent | | xxxxxxxxxxxx |
| t appid | | nginx |
| # bytes | | 46 |
| t domain | | xxxxxxxxxxxx |
| t fields.bank | | xxxxxxxxxxxx |
| t fields.env | | Production |
| t host | | xxxxxxxxxxxx |
| t message | | xxxxxxxxxxxx |
| # proc\_time | | 0.022 |
| t remote\_ip | | xxxxxxxxxxxx |
| t request | | xxxxxxxxxxxx |
| t response | | 200 |
| t source | | xxxxxxxxxxxx |
| t tags | | xxxxxxxxxxxx |
| t timestamp | | 11/Dec/2018:13:06:36 +0530 |
| t upstream\_addr | | xxxxxxxxxxxx |
| t user\_agent.build | | |
| t user\_agent.device | | Other |
| t user\_agent.major | | 40 |
| t user\_agent.minor | | 0 |
| t user\_agent.name | | Firefox |
| t user\_agent.os | | Windows 7 |
| t user\_agent.os\_name | | Windows 7 |
| t verb | | GET |

---

<div class="post-metadata">

**Author:** ![jen-huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jen-huang/32/74327_2.png) [@jen-huang](https://discuss.elastic.co/u/jen-huang)\
**Post date:** [December 11, 2018, 10:09pm UTC](https://discuss.elastic.co/t/timelion-expression/160315/2 "2018-12-11T22:09:03Z")

</div>

Hi, the expression will depend on what you want to visualize. Please see the following references as a starting point:

[https://www.elastic.co/guide/en/kibana/current/timelion.html](https://www.elastic.co/guide/en/kibana/current/timelion.html)

> **[Getting Started with Time Series Analysis in Kibana](https://www.elastic.co/blog/timelion-tutorial-from-zero-to-hero)**
>
> A tutorial for timelion - the time series composer in Kibana - explaining everything you need to start working with timelion.

Your initial expression to filter to 200 response code may look something like this:  
`.es(q='response:200')`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2019, 10:09pm UTC](https://discuss.elastic.co/t/timelion-expression/160315/3 "2019-01-08T22:09:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
