# Timelion series matching specific field

**URL:** <https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [October 25, 2017, 12:23pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240 "2017-10-25T12:23:15Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanek640](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@sanek640](https://discuss.elastic.co/u/sanek640)\
**Post date:** [October 25, 2017, 12:23pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240/1 "2017-10-25T12:23:16Z")

</div>

Hi, i have a problem with my time series data in Timelion.  
For example, I have a set of cars, that have index 'car' and every document besides different metadata has the most important for me fields: **price** (i may collect several price value for the data) , **model** (e.g. Mercedes) and **date** (the appropriate data of the price for the model was got from the market)  
I want to gain time series data to see the price of the **specific** (e.g. only for Mercedes) car for this date,  
I started to use this query:  
.es(index=car, q='model:Mercedes', timefield='date', metric='max:price').color(ff0000)

then i try to change the model and watch the difference:  
.es(index=car, q='model:BMW', timefield='date', metric='max:price').color(ff0000)  
and i get **the same** chart, that is not true.

after this i tried to split the models in one chart:  
.es(index=car,split='model:5', timefield='date', metric='max:price').color(#ff0000)  
and i get only one line.

The thing that a i want to do may be got from the if conditional, but the if operator must be number or series, but i need the String: .es(q='model').if(eq, **Mercedes** ,.es(timefield='date', metric='max:price')) but it couldn't be done.

Of course, i 've checked that the data for different models is defferent and exist.  
Please, help me to get this data like i've described to you.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 25, 2017, 12:38pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240/2 "2017-10-25T12:38:52Z")

</div>

Hi @sanek640,

which Version of the Elastic Stack are you using? Would it be possible for you to show us the mapping of the `car` index?

---

<div class="post-metadata">

**Author:** ![sanek640](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@sanek640](https://discuss.elastic.co/u/sanek640)\
**Post date:** [October 25, 2017, 1:04pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240/3 "2017-10-25T13:04:41Z")

</div>

Elastic 5.6.3  
I can't provide the exact structure, but it is smthg like this. If you think the key may be in there, i may check:

> **Mapping**
>
> ```
> {
> "car": {
> "mappings": {
> "mycar": {
> "properties": {
> "price": {
> "type": "float"
> },
> "date": {
> "type": "data"
> },
> "model": {
> "type": "text"
> }
> }
> }
> }
> }
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 25, 2017, 1:25pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240/4 "2017-10-25T13:25:16Z")

</div>

I assume that `data` is supposed to mean `date` in this example? In order to split on the field `model` it would have to be indexed as a `keyword`. If you enter the queries `model:Mercedes` and `model:BMW` into the Discover search bar, do you see the correct subset of documents?

---

<div class="post-metadata">

**Author:** ![sanek640](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@sanek640](https://discuss.elastic.co/u/sanek640)\
**Post date:** [October 25, 2017, 1:27pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240/5 "2017-10-25T13:27:04Z")

</div>

"date" of course, sorry.  
In the primary mapping, "model" has field "keyword" with a type keyword, you are right.  
Yes, i see.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 25, 2017, 1:55pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240/6 "2017-10-25T13:55:37Z")

</div>

I tried reproducing the problem with the information I got from you so far, but failed. If you split on `model`, what is the label of the one series that is displayed?

---

<div class="post-metadata">

**Author:** ![sanek640](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@sanek640](https://discuss.elastic.co/u/sanek640)\
**Post date:** [October 25, 2017, 1:59pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240/7 "2017-10-25T13:59:43Z")

</div>

I will have 5 different labels, but all of them return the one line, like they are the same prices for all of the models, that is not right. i may hide every label and don't notice the changes, i will notice them only if i hide all of them.

---

<div class="post-metadata">

**Author:** ![sanek640](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@sanek640](https://discuss.elastic.co/u/sanek640)\
**Post date:** [October 25, 2017, 2:05pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240/8 "2017-10-25T14:05:26Z")

</div>

The problem is that i dont get the unique prices for the models, but i got the same whether i chose the BMV model or Mercedes

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 25, 2017, 2:11pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240/9 "2017-10-25T14:11:56Z")

</div>

Sorry, I misunderstood you there. So you get 5 identical series, which means that for each bucket the maximum price is the same.

To give me a better idea of how the values are distributed, would it be possible to run the following query after substituting the `<FROM>` and `<TO>` placeholders for the timestamps of the interval you are looking at in timelion and post the results?

```
GET car/_search
{
  "query": {
    "range": {
      "date": {
        "gte": <FROM>,
        "lte": <TO>
      }
    }
  },
  "size": 0, 
  "aggs": {
    "models": {
      "terms": {
        "field": "model",
        "size": 5
      },
      "aggs": {
        "price_stats": {
          "extended_stats": {
            "field": "price"
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2017, 2:12pm UTC](https://discuss.elastic.co/t/timelion-series-matching-specific-field/105240/10 "2017-11-22T14:12:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
