# Visualization with stat data

**URL:** <https://discuss.elastic.co/t/visualization-with-stat-data/33745>\
**Category:** Kibana\
**Created:** [November 4, 2015, 1:39pm UTC](https://discuss.elastic.co/t/visualization-with-stat-data/33745 "2015-11-04T13:39:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![raffis](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@raffis](https://discuss.elastic.co/u/raffis)\
**Post date:** [November 4, 2015, 1:39pm UTC](https://discuss.elastic.co/t/visualization-with-stat-data/33745/1 "2015-11-04T13:39:50Z")

</div>

I want to create graphs with stat data, but I've realized that this is impossible as far as I understood kibana correctly.  
@see similar topics: [How to get latest entry for all users](https://discuss.elastic.co/t/how-to-get-latest-entry-for-all-users/29222)

I just wrote a big nagios performance data filter for logstash, and just realized I can't create visualizations which make sense.  
For example:  
How can I create a metric number with the current RAM Usage over multiple host?  
How can I create a line chart with RAM Usage over one day (x=Date Histogram, y=Ram Usage)?

This seems impossible because I always get the sum of the stat data which clearly doesn't make any sense.

Kibana Filter: host:vmhost\* AND nagios.service.raw:"VMware ESXi Host Memory"

Data example:  
{host:vmhost1.example.org, nagios.service:"VMware ESXi Host Memory": 133,000, nagios.unit:"MB"}  
{host:vmhost2.example.org, nagios.service:"VMware ESXi Host Memory": 70,000, nagios.unit:"MB"}  
{host:vmhost1.example.org, nagios.service:"VMware ESXi Host Memory": 134,430, nagios.unit:"MB"}  
{host:vmhost2.example.org, nagios.service:"VMware ESXi Host Memory": 69,545, nagios.unit:"MB"}  
{host:vmhost1.example.org, nagios.service:"VMware ESXi Host Memory": 152,430, nagios.unit:"MB"}  
{host:vmhost2.example.org, nagios.service:"VMware ESXi Host Memory": 65,444, nagios.unit:"MB"}

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [November 5, 2015, 3:57am UTC](https://discuss.elastic.co/t/visualization-with-stat-data/33745/2 "2015-11-05T03:57:57Z")

</div>

So, it's true that you can't get the current (latest) value - there is no aggregation exposed in Kibana that will give you that. Feel free to +1 this ticket: [https://github.com/elastic/kibana/issues/678](https://github.com/elastic/kibana/issues/678)

However, you should be able to get the overtime chart you described by using the "Avg" aggregation on the Y-axis. In fact, that is exactly what we do in [Topbeat](https://www.elastic.co/downloads/beats/topbeat). Note that in this case, the indexed value was in bytes, and I used a [field formatter](https://www.elastic.co/blog/kibana-4-1-field-formatters) to display it in MB.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/7/771a7937b5582f3d8a865b1c51538d9086569ff1.png)

---

<div class="post-metadata">

**Author:** ![raffis](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@raffis](https://discuss.elastic.co/u/raffis)\
**Post date:** [November 5, 2015, 9:12am UTC](https://discuss.elastic.co/t/visualization-with-stat-data/33745/3 "2015-11-05T09:12:17Z")

</div>

> [@tbragin](#):
>
> However, you should be able to get the overtime chart you described by using the "Avg" aggregation on the Y-axis. In fact, that is exactly what we do in Topbeat. Note that in this case, the indexed value was in bytes, and I used a field formatter to display it in MB.

Yeah this is working fine with one server but not with multiple server.  
With multiple server I get the average between them which is actually wrong.  
What I need is the average of each and then the sum() of that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:09pm UTC](https://discuss.elastic.co/t/visualization-with-stat-data/33745/4 "2017-07-06T14:09:49Z")

</div>


