# Timelion query filter returning constant 0 results

**URL:** <https://discuss.elastic.co/t/timelion-query-filter-returning-constant-0-results/323625>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [January 20, 2023, 7:16pm UTC](https://discuss.elastic.co/t/timelion-query-filter-returning-constant-0-results/323625 "2023-01-20T19:16:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vector\_prime](https://avatars.discourse-cdn.com/v4/letter/v/f17d59/32.png) [@vector\_prime](https://discuss.elastic.co/u/vector_prime)\
**Post date:** [January 20, 2023, 7:16pm UTC](https://discuss.elastic.co/t/timelion-query-filter-returning-constant-0-results/323625/1 "2023-01-20T19:16:46Z")

</div>

I have an index with the following document structure:

```auto
"_source": {
    "installcreatedbyusername": "xxxx",
    "@timestamp": "2023-01-20T16:30:03.840332Z",
    "type": "aegis",
    "num_packages": 2,
    "num_environments": 14,
    "is_stage_only": true,
    "end_time": "2023-01-20T12:14:24.252083Z",
    "installisoutageconfirmed": true,
    "@version": "1",
    "changestatusname": "Finished",
    "install_id": 7005,
    "start_time": "2023-01-20T12:04:28.799086Z",
    "total_time_taken": 595.452997,
    "install_type": "NONPROD",
    "installname": "xxxxxxxx",
    "installissqlregenrequired": true,
    "installoutagetype": "xxxxxxxxx",
    "environment_names": "xxxxxxxxxx",
    "installcreateddatetime": "2023-01-20T12:04:28.797302Z"
  }

```

I am trying to generate a timelion graph for manual vs automated effort, and things appear to work, until I add in a query to start filtering my data.

My timelion queries (3rd is the one with the issue):

```auto
.es(index=aegis*,timefield=@timestamp,metric=cardinality:install_id,).multiply(50).divide(60).label("Engineer Time - NO Automation (hours)"),
.es(index=aegis*,timefield=@timestamp,metric=cardinality:install_id,).multiply(5).divide(60).label("Engineer Time - WITH Automation (hours)"),
.es(q='changestatusname: "Finished"', index=aegis*, timefield=@timestamp, metric=count:install_id).label('Finished Count')

```

Screenshot of my current results:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/4/64a58a7478314d487a96b904af0072439a885eae.png)

You can see that the 'Finished Count' line is always zero, when I know that is incorrect. What am I doing wrong here?

---

<div class="post-metadata">

**Author:** ![vector\_prime](https://avatars.discourse-cdn.com/v4/letter/v/f17d59/32.png) [@vector\_prime](https://discuss.elastic.co/u/vector_prime)\
**Post date:** [January 23, 2023, 9:52pm UTC](https://discuss.elastic.co/t/timelion-query-filter-returning-constant-0-results/323625/2 "2023-01-23T21:52:50Z")

</div>

In case this helps others, my index timefield was NOT @timestamp, so correcting to use the actual timefield fixed my issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2023, 9:53pm UTC](https://discuss.elastic.co/t/timelion-query-filter-returning-constant-0-results/323625/3 "2023-02-20T21:53:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
