# View Timelion data for all indices

**URL:** https://discuss.elastic.co/t/view-timelion-data-for-all-indices/207099
**Category:** Kibana
**Tags:** timelion
**Created:** [November 8, 2019, 11:33am UTC](https://discuss.elastic.co/t/view-timelion-data-for-all-indices/207099 "2019-11-08T11:33:31Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)
#### Post date: [November 8, 2019, 11:33am UTC](https://discuss.elastic.co/t/view-timelion-data-for-all-indices/207099/1 "2019-11-08T11:33:31Z")

</div>

Hi,

I want to visualize the amount of logs indexed per day for each index-pattern that we have. For example, say that we have 5 index patterns. I want to create a Timelion chart that includes each one of these and lists how much events are being ingested in elasticsearch per day.

Some pseudocode:

`.es(split=index)`

Is this possible?

---

<div class="post-metadata">

### Author: ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)
#### Post date: [November 15, 2019, 10:03am UTC](https://discuss.elastic.co/t/view-timelion-data-for-all-indices/207099/2 "2019-11-15T10:03:07Z")

</div>

Hi @victor.nilsson  
you are on the right direction, when using split you have also to specify the max number of series you are going to draw. Also to be completely sure you should specify the timefield field to use when querying your data.

I've tested locally that this will work:

```auto
.es(index=kibana_sample_data_logs*,timefield=timestamp,split=_index:10)

```

in this example I've reindexes the `kibana_sample_data_logs` example files into 4 different indices with a POST like the following:

```auto
POST _reindex
{
  "source": {
    "index": "kibana_sample_data_logs"
  },
  "dest": {
    "index": "kibana_sample_data_logs_2"
  },
  "script": {
    "source": "ctx._index = \"kibana_sample_data_logs_2\""
  }
}

```

---

<div class="post-metadata">

### Author: ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)
#### Post date: [November 15, 2019, 12:14pm UTC](https://discuss.elastic.co/t/view-timelion-data-for-all-indices/207099/3 "2019-11-15T12:14:35Z")

</div>

Awesome! Thanks.

I've run into an issue though, if i run the following:

```
.es(index=logstash-*,timefield=@timestamp,split=_index:10)

```

I get the following error:

> Timelion: Error: in cell #1: [index\_closed\_exception] closed, with { index\_uuid="hYgo4eqsQqOxCuT3qMz9tA" & index="logstash-test-2019-09-10" }

Is there a way to not let timelion search in closed indices?

---

<div class="post-metadata">

### Author: ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)
#### Post date: [November 15, 2019, 12:34pm UTC](https://discuss.elastic.co/t/view-timelion-data-for-all-indices/207099/4 "2019-11-15T12:34:11Z")

</div>

What version of kibana are you running? I'm testing on 7.3 and it just ignore closed indices

---

<div class="post-metadata">

### Author: ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)
#### Post date: [November 15, 2019, 2:54pm UTC](https://discuss.elastic.co/t/view-timelion-data-for-all-indices/207099/5 "2019-11-15T14:54:38Z")

</div>

Ah, we're still on 6.6. We're planning an upgrade next tuesday. I'll you know how the search goes after that.

Thanks!

---

<div class="post-metadata">

### Author: ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)
#### Post date: [November 15, 2019, 9:21pm UTC](https://discuss.elastic.co/t/view-timelion-data-for-all-indices/207099/6 "2019-11-15T21:21:19Z")

</div>

This should work for your usecase `.es(index=*,split=_index:5)`. [\_index](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-index-field.html) is a virtual field that allows for aggregating on index name.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 13, 2019, 9:21pm UTC](https://discuss.elastic.co/t/view-timelion-data-for-all-indices/207099/7 "2019-12-13T21:21:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
