# Unable to use stats on field

**URL:** <https://discuss.elastic.co/t/unable-to-use-stats-on-field/32217>\
**Category:** Kibana\
**Created:** [October 14, 2015, 9:06pm UTC](https://discuss.elastic.co/t/unable-to-use-stats-on-field/32217 "2015-10-14T21:06:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![etfeet](https://avatars.discourse-cdn.com/v4/letter/e/4da419/32.png) [@etfeet](https://discuss.elastic.co/u/etfeet)\
**Post date:** [October 14, 2015, 9:06pm UTC](https://discuss.elastic.co/t/unable-to-use-stats-on-field/32217/1 "2015-10-14T21:06:34Z")

</div>

I have a field that i'm trying to use for stats. However, kibana is not displaying any data.

In logstash im using ruby code to add the value of two fields into a third one. I'm trying to graph the value of the third one. However, no values show up in the stats pannel.

I've tried using a mutate filter to format the resulting field as float or integer. However, that didn't help.

```
if [bytes_sent] and [bytes_rcvd] {
      ruby { code => "event['bytes'] = event['bytes_sent'] + event['bytes_rcvd']" }
} else if [bytes_sent] {
mutate {
  rename => ["bytes_sent", "bytes"]
}
} elseif [bytes_rcvd] {
mutate {
  rename => ["bytes_rcvd", "bytes"]
}
} else { }

```

logstash output:

```
      "message" => "2015-03-18T23:59:41.802932-07:00 x.x.x.x id=my_host sn=my_sn_number time=\"2015-03-19 00:02:27\" fw=x.x.x.x pri=6 c=1024 m=537 msg=\" Connection Closed\" n=14957 src=x.x.x.x:123:X1 dst=x.x.x.x:123:X1 proto=udp/ntp sent=380 rcvd=380 ",
     "@version" => "1",
   "@timestamp" => "2015-10-14T21:00:52.213Z",
         "path" => "/tmp/sonicwall.log",
         "type" => "fw-sonicwall",
         "tags" => [
    [0] "sonicwall",
    [1] "firewall_log"
],
           "id" => "booth_firewall",
         "time" => "2015-03-19 00:02:27",
          "msg" => "Connection Closed",
        "proto" => "udp/ntp",
    "msg_count" => "14957",
       "msg_id" => "537",
 "msg_category" => "1024",
 "msg_priority" => "6",
"serial_number" => "C0EAE490A1A6",
       "src_ip" => "x.x.x.x",
     "src_port" => "123",
"src_interface" => "X1",
       "dst_ip" => "x.x.x.x",
     "dst_port" => "123",
"dst_interface" => "X1",
       "action" => "Closed",
   "bytes_sent" => 380,
   "bytes_rcvd" => 380,
        "bytes" => 760,
  "application" => "NTP",
"logstash_host" => "logstash-dev",
         "host" => "x.x.x.x"
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 14, 2015, 9:36pm UTC](https://discuss.elastic.co/t/unable-to-use-stats-on-field/32217/2 "2015-10-14T21:36:56Z")

</div>

What is the field mapped as in Elasticsearch?

---

<div class="post-metadata">

**Author:** ![etfeet](https://avatars.discourse-cdn.com/v4/letter/e/4da419/32.png) [@etfeet](https://discuss.elastic.co/u/etfeet)\
**Post date:** [October 15, 2015, 12:38am UTC](https://discuss.elastic.co/t/unable-to-use-stats-on-field/32217/3 "2015-10-15T00:38:39Z")

</div>

below is the output from elastic. Ican graph the bytes\_rcvd and bytes\_sent fields just fine. However, I can't graph the bytes field.

```
      "bytes" : {
        "type" : "long"
      },
      "bytes_rcvd" : {
        "type" : "long"
      },
      "bytes_sent" : {
        "type" : "long"
      },
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 15, 2015, 12:52am UTC](https://discuss.elastic.co/t/unable-to-use-stats-on-field/32217/4 "2015-10-15T00:52:08Z")

</div>

Does it show the field in the discover field? And if so does it show the data for it?

---

<div class="post-metadata">

**Author:** ![etfeet](https://avatars.discourse-cdn.com/v4/letter/e/4da419/32.png) [@etfeet](https://discuss.elastic.co/u/etfeet)\
**Post date:** [October 16, 2015, 8:09pm UTC](https://discuss.elastic.co/t/unable-to-use-stats-on-field/32217/5 "2015-10-16T20:09:17Z")

</div>

The field shows up in discover and the field is populated with data. ie 10.0 (float) or 10 ( integer).

If i make a chart graph or a histogram, terms, etc. the field works as expected. However, it does not work when I try to use it with stats.

for reference I'm pulling log data out of a dell sonicwall NSA firewall and trying to combine the value into a single field so I can compare against dell, juniper, etc firewalls.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:11pm UTC](https://discuss.elastic.co/t/unable-to-use-stats-on-field/32217/6 "2017-07-06T14:11:09Z")

</div>


