# Timelion : packetbeat per IPs bytes usage on bits per second

**URL:** <https://discuss.elastic.co/t/timelion-packetbeat-per-ips-bytes-usage-on-bits-per-second/90854>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [June 26, 2017, 4:36pm UTC](https://discuss.elastic.co/t/timelion-packetbeat-per-ips-bytes-usage-on-bits-per-second/90854 "2017-06-26T16:36:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [June 26, 2017, 4:36pm UTC](https://discuss.elastic.co/t/timelion-packetbeat-per-ips-bytes-usage-on-bits-per-second/90854/1 "2017-06-26T16:36:21Z")

</div>

Using packetbeat to analyse my server traffic. there is no issue on data insert.

I tried the below query to view the IP [byes\_in] inbound usage metrics on Timelion. But getting different graph pattern. I compared it with normal network usage tools [MRTG].

I used packetbeat default settings [period - 10s]

.es(index=packetbeat-\*,q=dest.ip:172.16.10.10,metric=avg:dest.stats.net\_bytes\_total).divide(10).multiply(8)

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [June 26, 2017, 9:44pm UTC](https://discuss.elastic.co/t/timelion-packetbeat-per-ips-bytes-usage-on-bits-per-second/90854/2 "2017-06-26T21:44:32Z")

</div>

Any chance you could post what you're seeing and what you expect? It would be helpful for understanding what might be wrong.

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [June 27, 2017, 4:14am UTC](https://discuss.elastic.co/t/timelion-packetbeat-per-ips-bytes-usage-on-bits-per-second/90854/3 "2017-06-27T04:14:10Z")

</div>

**Timelion Graph:**

 ![](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c1e57478316fee0779fede15f36c166597960a80.png)

**Another tool graph:**

 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d3537a976b6a59e75bc523a6b475b0ee09034a47.png)

**Sample data:**

 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/a/2a821711e4d509358fb3dd85dfc2925f6988b540.png)

**Timelion Query:**

.es(index=packetsflow-_,q=dest.ip:10.21.98.204,metric=avg:dest.stats.net\_bytes\_total).divide(10).multiply(8).title(Bandwidth).label(In).yaxis(units=bits/s),  
.es(index=packetsflow-_,q=dest.ip:10.21.98.204,metric=avg:source.stats.net\_bytes\_total).divide(10).multiply(8).title(Bandwidth).label(Out).yaxis(units=bits/s)

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [June 27, 2017, 5:07pm UTC](https://discuss.elastic.co/t/timelion-packetbeat-per-ips-bytes-usage-on-bits-per-second/90854/4 "2017-06-27T17:07:40Z")

</div>

The time range on the two graphs here isn't the same, there's very little overlap, so it's hard to see if the data looks the same or not. The fluctuations you see in timelion aren't really visible in the other graph. This is the overlapping view:

## Timelion

 ![](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f98cdc2a44be54a0ef613a3505403aeaab939eda.png)

## Other tool

![](https://us1.discourse-cdn.com/elastic/original/3X/2/8/28bb572b7d920b0fdeb0a3f90a88090368daa78b.png)

But maybe you just mean the values are off (~700kbps vs ~6mbps). I believe the problem there is your math. Why are you dividing the value by 10 before you multiply it by 8? There are 8 bits in a byte, and since you're trying to convert bytes to bits, you need only multiply by 8.

So if we look at the output value at, say, 9:26, that value looks to be about 640kB/s. 640kB/s \* 8 = 5120kbps. The graph on the other tool seems to be closer to 6000kbps. That's a sizable discrepancy, and I'm not sure why. Assuming that other tool is traffic from the same box/IP, I would indeed expect the numbers to be closer. Perhaps the time bucketing is different between the two, and that's why the average values are a bit different? I'm not sure I buy that though.

Is it possible to compare the values you see at a given time between the 2 tools? Not the average value, but the value at a single slice of time. That way you could see if the source records are off.

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [June 28, 2017, 2:25pm UTC](https://discuss.elastic.co/t/timelion-packetbeat-per-ips-bytes-usage-on-bits-per-second/90854/5 "2017-06-28T14:25:29Z")

</div>

thanks for your reply.

And let me check and update you.

btw, reason for divide the value by 10 is, packetbeat sends the data for every 10s once. So If I need to get the seconds data, then I should divide the value by 10. so that I can get per second data. Am I right , please correct if its wrong.

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [June 28, 2017, 5:48pm UTC](https://discuss.elastic.co/t/timelion-packetbeat-per-ips-bytes-usage-on-bits-per-second/90854/6 "2017-06-28T17:48:56Z")

</div>

No, that's not actually correct. Elasticsearch does that for you as part of the query. You are asking it "given whatever records you have, over a specific period of time (the time picker range), give me the average values bucketed up by some time interval (slices of that overall range)". It doesn't matter what your sampling rate is, or how many records are there, it'll give you that average. Of course, if the sampling rate is 10 seconds, and you ask for a value sliced up by less than that, it can sometimes give you some weird extrapolated results, but that's kind of a tangent here.

The bottom line is, you don't need to, and in fact should not, account for the sampling rate in of the data when you are doing a query. That's Elasticsearch's whole job.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2017, 5:49pm UTC](https://discuss.elastic.co/t/timelion-packetbeat-per-ips-bytes-usage-on-bits-per-second/90854/7 "2017-07-26T17:49:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
