# UDP Message from Filebeat to ElasticSearch to Grafana - How to filter for my value?

**URL:** <https://discuss.elastic.co/t/udp-message-from-filebeat-to-elasticsearch-to-grafana-how-to-filter-for-my-value/258302>\
**Category:** Elasticsearch\
**Created:** [December 10, 2020, 3:40pm UTC](https://discuss.elastic.co/t/udp-message-from-filebeat-to-elasticsearch-to-grafana-how-to-filter-for-my-value/258302 "2020-12-10T15:40:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dewell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dewell/32/84214_2.png) [@dewell](https://discuss.elastic.co/u/dewell)\
**Post date:** [December 10, 2020, 3:40pm UTC](https://discuss.elastic.co/t/udp-message-from-filebeat-to-elasticsearch-to-grafana-how-to-filter-for-my-value/258302/1 "2020-12-10T15:40:04Z")

</div>

Hello,  
with the help of several guides I tried to show a constant UDP stream of double values (10 8byte double values each second) in a line chart in Grafana but I'm not sure how to get the value from elasticsearch into the Grafana line chart.

The stack I chose for this should be as simple as possible and i took:  
UDP Input Plugin for Filebeat -\> Elasticsearch -\> Grafana

Here is the configuration of the filebeats.yaml file:  
 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/1/5/15cad40b3d56d4c3d5acf8011869275b2e882da4.png)

The connection to elasticsearch is established and works, filebeat is publishing the correct amount of values every 30 seconds (300 publishes)

My question is: How do I have to configure my Grafana to connect these values now into a realtime chart? What to choose for the metric? What field should I see there? (I assume the one I put into the filebeat.yaml but i can't find it)

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/1/0/1041e8eee2dfafb3efdd9cb18a1428f5187aa54b.png)

---

<div class="post-metadata">

**Author:** ![dewell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dewell/32/84214_2.png) [@dewell](https://discuss.elastic.co/u/dewell)\
**Post date:** [December 15, 2020, 8:52am UTC](https://discuss.elastic.co/t/udp-message-from-filebeat-to-elasticsearch-to-grafana-how-to-filter-for-my-value/258302/2 "2020-12-15T08:52:06Z")

</div>

I guess I failed to make clear what the problem is ☹

Right now I receive the data if I choose "COUNT as metric. The number of package within a certain timeframe is displayed then. But I haven't managed yet to get the actual double value out of each package. AVG or MAX don't show anything since I can't find the right "field".

According to my filebeat.yml file I'd expect to see "elasticsearch.udp\_test\_1" or something in the field tag of the Metric of my Grafana query but there are just hundreds of standard options for all kinds of data sources but not the field I configured.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2021, 8:52am UTC](https://discuss.elastic.co/t/udp-message-from-filebeat-to-elasticsearch-to-grafana-how-to-filter-for-my-value/258302/3 "2021-01-12T08:52:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
