# Use Kibana to find API endpoints with most number of inter-service calls

**URL:** <https://discuss.elastic.co/t/use-kibana-to-find-api-endpoints-with-most-number-of-inter-service-calls/89481>\
**Category:** Kibana\
**Created:** [June 15, 2017, 1:19am UTC](https://discuss.elastic.co/t/use-kibana-to-find-api-endpoints-with-most-number-of-inter-service-calls/89481 "2017-06-15T01:19:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![feicipet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/feicipet/32/8056_2.png) [@feicipet](https://discuss.elastic.co/u/feicipet)\
**Post date:** [June 15, 2017, 1:19am UTC](https://discuss.elastic.co/t/use-kibana-to-find-api-endpoints-with-most-number-of-inter-service-calls/89481/1 "2017-06-15T01:19:19Z")

</div>

Hi,

I have a bunch of microservices that are calling each other. Say I have serviceA, serviceB and serviceC, the call sequence may look like:

API GW -\> ServiceA.endpointA1 -\> ServiceB.endpointB1 -\> ServiceC.endpointC2

Each endpoint invoked will send a log to ES. In the logs that ship to ES, I have the following fields:

1. api.correlationid - this is a common correlation ID that links all endpoints invoked in one call flow (similar to Zipkin's traceID)
2. api.command - e.g. POST /v1/login
3. api.source - This indicates the source where the call was made from. If ServiceB gets a call from ServiceA, in ServiceB request logs, api.source would denote "ServiceA" (kinda like a referrer)

With this information, I have traceability throughout all the microservices for each individual request.

But now I want to aggregate the information to show, for e.g.: Which first contact endpoint (the endpoint that was invoked directly from API Gateway) has the most number of inter-service calls following it.

Aggregating the count of API calls by api.correlationid is easy enough to do but having a bunch of arbitrary correlation IDs is not very useful. I want to further aggregate these correlation IDs under the api.command they are associated to (kind of like a subquery).

Is this possible in Kibana?

Thanks  
Wong

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [June 15, 2017, 8:59am UTC](https://discuss.elastic.co/t/use-kibana-to-find-api-endpoints-with-most-number-of-inter-service-calls/89481/2 "2017-06-15T08:59:59Z")

</div>

Do you have a reliable way to sort the events so that the first event would be the first contact endpoint? If so you might be able to use a "top hits" metric and concatenate the `api.command` from the first event within each `api.correlationid` bucket.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2017, 9:00am UTC](https://discuss.elastic.co/t/use-kibana-to-find-api-endpoints-with-most-number-of-inter-service-calls/89481/3 "2017-07-13T09:00:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
