# Timestamp distribution hour of day

**URL:** https://discuss.elastic.co/t/timestamp-distribution-hour-of-day/17851
**Category:** Elasticsearch
**Created:** [June 2, 2014, 1:55am UTC](https://discuss.elastic.co/t/timestamp-distribution-hour-of-day/17851 "2014-06-02T01:55:35Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![kevins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevins/32/946_2.png) [@kevins](https://discuss.elastic.co/u/kevins)
#### Post date: [June 2, 2014, 1:55am UTC](https://discuss.elastic.co/t/timestamp-distribution-hour-of-day/17851/1 "2014-06-02T01:55:35Z")

</div>

All the events in my index are \_timestamp enabled. I would like to look at  
a distribution of events based on the hour of day.

Here is an example of what I would like to query:

[http://blog.redowlanalytics.com/post/78135922786/generating-realistic-fake-communications-data](http://blog.redowlanalytics.com/post/78135922786/generating-realistic-fake-communications-data)

Is that possible? Can that be done on a histogram in kibana?

Thank you.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/6dad4af2-bc57-4326-9619-0d5eb4d9d6ba%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/6dad4af2-bc57-4326-9619-0d5eb4d9d6ba%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [June 2, 2014, 4:57am UTC](https://discuss.elastic.co/t/timestamp-distribution-hour-of-day/17851/2 "2014-06-02T04:57:41Z")

</div>

Did you try an histogram on \_timestamp?

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 2 juin 2014 à 03:55, Kevin S [kevinsteger@gmail.com](mailto:kevinsteger@gmail.com) a écrit :

All the events in my index are \_timestamp enabled. I would like to look at a distribution of events based on the hour of day.

Here is an example of what I would like to query:

[http://blog.redowlanalytics.com/post/78135922786/generating-realistic-fake-communications-data](http://blog.redowlanalytics.com/post/78135922786/generating-realistic-fake-communications-data)

Is that possible? Can that be done on a histogram in kibana?

## Thank you.

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/6dad4af2-bc57-4326-9619-0d5eb4d9d6ba%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/6dad4af2-bc57-4326-9619-0d5eb4d9d6ba%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5A7B98DB-C9FB-41E1-87C1-A69F82396C3B%40pilato.fr](https://groups.google.com/d/msgid/elasticsearch/5A7B98DB-C9FB-41E1-87C1-A69F82396C3B%40pilato.fr).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![Patrick\_Proniewski](https://avatars.discourse-cdn.com/v4/letter/p/96bed5/32.png) [@Patrick\_Proniewski](https://discuss.elastic.co/u/Patrick_Proniewski)
#### Post date: [June 2, 2014, 5:16am UTC](https://discuss.elastic.co/t/timestamp-distribution-hour-of-day/17851/3 "2014-06-02T05:16:19Z")

</div>

hello,

I don't see how an histogram on \_timestamp could be a solution. If I understand correctly, Kevin is looking for a way to create histogram on "hour of \_timestamp", so every events between 2am and 3am should be in the same bin even if they belong to different days.

On 02 juin 2014, at 06:57, David Pilato wrote:

> Did you try an histogram on \_timestamp?
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 2 juin 2014 à 03:55, Kevin S [kevinsteger@gmail.com](mailto:kevinsteger@gmail.com) a écrit :
> 
> All the events in my index are \_timestamp enabled. I would like to look at a distribution of events based on the hour of day.
> 
> Here is an example of what I would like to query:
> 
> [http://blog.redowlanalytics.com/post/78135922786/generating-realistic-fake-communications-data](http://blog.redowlanalytics.com/post/78135922786/generating-realistic-fake-communications-data)
> 
> Is that possible? Can that be done on a histogram in kibana?
> 
> Thank you.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/D0341EC0-1EA0-4C98-A56D-6109ED8E3DC6%40patpro.net](https://groups.google.com/d/msgid/elasticsearch/D0341EC0-1EA0-4C98-A56D-6109ED8E3DC6%40patpro.net).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![kevins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevins/32/946_2.png) [@kevins](https://discuss.elastic.co/u/kevins)
#### Post date: [June 2, 2014, 3:43pm UTC](https://discuss.elastic.co/t/timestamp-distribution-hour-of-day/17851/4 "2014-06-02T15:43:19Z")

</div>

That is correct. Events between 2-3am even on different days would appear  
in the same "bucket"

On Sunday, June 1, 2014 10:16:33 PM UTC-7, Patrick Proniewski wrote:

> hello,
> 
> I don't see how an histogram on \_timestamp could be a solution. If I  
> understand correctly, Kevin is looking for a way to create histogram on  
> "hour of \_timestamp", so every events between 2am and 3am should be in the  
> same bin even if they belong to different days.
> 
> On 02 juin 2014, at 06:57, David Pilato wrote:
> 
> > Did you try an histogram on \_timestamp?
> > 
> > --  
> > David 😉  
> > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > 
> > Le 2 juin 2014 à 03:55, Kevin S \<[kevin...@gmail.com](mailto:kevin...@gmail.com) \<javascript:\>\> a  
> > écrit :
> > 
> > All the events in my index are \_timestamp enabled. I would like to look  
> > at a distribution of events based on the hour of day.
> > 
> > Here is an example of what I would like to query:
> 
> [http://blog.redowlanalytics.com/post/78135922786/generating-realistic-fake-communications-data](http://blog.redowlanalytics.com/post/78135922786/generating-realistic-fake-communications-data)
> 
> > Is that possible? Can that be done on a histogram in kibana?
> > 
> > Thank you.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/f489a71a-1909-44c0-abaa-731326df1bb9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f489a71a-1909-44c0-abaa-731326df1bb9%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![Antonio\_Augusto\_Sant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antonio_augusto_sant/32/82851_2.png) [@Antonio\_Augusto\_Sant](https://discuss.elastic.co/u/Antonio_Augusto_Sant)
#### Post date: [June 2, 2014, 4:34pm UTC](https://discuss.elastic.co/t/timestamp-distribution-hour-of-day/17851/5 "2014-06-02T16:34:26Z")

</div>

I was looking for this myself the other day.  
You can get the results you want from ES with the following aggregation:

{  
"aggs": {  
"hour": {  
"terms": {  
"script": "doc['@timestamp'].date.hourOfDay"  
}  
}  
}  
}

For Kibana, you'd probably need a Histogram panel that is note date based.  
That is, you need a custom Kibana panel.

On Sunday, June 1, 2014 10:55:36 PM UTC-3, Kevin S wrote:

> All the events in my index are \_timestamp enabled. I would like to look  
> at a distribution of events based on the hour of day.
> 
> Here is an example of what I would like to query:
> 
> [http://blog.redowlanalytics.com/post/78135922786/generating-realistic-fake-communications-data](http://blog.redowlanalytics.com/post/78135922786/generating-realistic-fake-communications-data)
> 
> Is that possible? Can that be done on a histogram in kibana?
> 
> Thank you.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4f04cafa-d6bb-403d-876e-d6ed7f5f52c5%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4f04cafa-d6bb-403d-876e-d6ed7f5f52c5%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 1:25am UTC](https://discuss.elastic.co/t/timestamp-distribution-hour-of-day/17851/6 "2017-07-06T01:25:12Z")

</div>


