# Timelion - Second part of query ignored

**URL:** <https://discuss.elastic.co/t/timelion-second-part-of-query-ignored/85008>\
**Category:** Kibana\
**Created:** [May 9, 2017, 4:31am UTC](https://discuss.elastic.co/t/timelion-second-part-of-query-ignored/85008 "2017-05-09T04:31:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [May 9, 2017, 4:31am UTC](https://discuss.elastic.co/t/timelion-second-part-of-query-ignored/85008/1 "2017-05-09T04:31:16Z")

</div>

Hi,

I'm having a issue with a query that I can't figure out. For some reason the second part of my query is always the same as the first part of my query.

```auto

```

When I make two simple metrics to show the sum of in\_bytes with the above queries I do get the correct numbers so it's not a data problem. When I switch src\_addr and dst\_addr the results are also reversed (two lines showing the exact same data based on dst\_addr instead of src\_addr).

Looks like somehow the results from the first part of the query are copied to the second.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [May 9, 2017, 9:47am UTC](https://discuss.elastic.co/t/timelion-second-part-of-query-ignored/85008/2 "2017-05-09T09:47:10Z")

</div>

Hi @Sjaak01,

what version of Kibana are you using? Are you using any plugins for Timelion?

---

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [May 9, 2017, 11:52pm UTC](https://discuss.elastic.co/t/timelion-second-part-of-query-ignored/85008/3 "2017-05-09T23:52:08Z")

</div>

> [@weltenwort](#):
>
> Hi @Sjaak01,
> 
> what version of Kibana are you using? Are you using any plugins for Timelion?

5.3.

I'm using this plugin ([Bytes per second - Is it possible? - #14 by rashid](https://discuss.elastic.co/t/bytes-per-second-is-it-possible/83497/14)) to help my graphs look correct.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [May 10, 2017, 9:41am UTC](https://discuss.elastic.co/t/timelion-second-part-of-query-ignored/85008/4 "2017-05-10T09:41:41Z")

</div>

The reason seems to be that all assignments to the variable `$q` are evaluated before the other parts of the expression are evaluated. This means that the second assignment to `$q` (containing the `netflow.ipv4_dst_addr` filter) is also what is used in the first `.es()` clause. Introducing a second variable instead of reassigning should solve the issues, i.e.:

```
$src_query='vessel_name:Vessel_1 AND **netflow.ipv4_src_addr** :1.2.3.4', $dst_query='vessel_name:Vessel_1 AND **netflow.ipv4_dst_addr** :1.2.3.4', .es($src_query,metric='sum:netflow.in_bytes').mvavg(3m).scale_interval(1s).divide(1024).label('Up - KBps'), .es($dst_query,metric='sum:netflow.in_bytes').mvavg(3m).scale_interval(1s).divide(1024).label('Down - KBps')
```

---

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [May 11, 2017, 1:34am UTC](https://discuss.elastic.co/t/timelion-second-part-of-query-ignored/85008/5 "2017-05-11T01:34:30Z")

</div>

Cool, didn't know you could use variables.

Looks like it's working using your example. I had to remove the \*\* \*\* though to get it working.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [May 11, 2017, 8:22am UTC](https://discuss.elastic.co/t/timelion-second-part-of-query-ignored/85008/6 "2017-05-11T08:22:46Z")

</div>

Great 👍 You were using variables in your original query already (`$q=`...) 🤔 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2017, 8:22am UTC](https://discuss.elastic.co/t/timelion-second-part-of-query-ignored/85008/7 "2017-06-08T08:22:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
