# Visualize 2 lines - 2 nodes with 1 parameter per time

**URL:** <https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240>\
**Category:** Kibana\
**Created:** [November 21, 2020, 7:13pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240 "2020-11-21T19:13:15Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [November 21, 2020, 7:13pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/1 "2020-11-21T19:13:15Z")

</div>

Good morning!

After intensive search It seems to me that it is impossible. Anyway, maybe someone have an idea to implement it(with Kibana, or, maybe Zabbix + prometheus)...

The case is I have a **system consists of many nodes**. And have an utility that saves state of a system every 5 minutes in txt:

 ![system state](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a6265fca8cee9b44fae11ed86743f4a6166d5afd.jpeg)  
So I can see for every node some diagnostic parameters for every timestamp:  
-quantity of errors  
-quantity of input messages  
-quantity of output messages  
...

The goal is to make a graph with some of the nodes visualising one of the parameter, for example  
-quantity of input messages per 5 minutes

I did it with Excel well:

1. Parsed this source file into csv
2. Opened with Excel
3. Made graph

How do it with Kibana?

For 1 node it worked perfect:

1. I parsed this source file into json:  
 ![json](https://us1.discourse-cdn.com/elastic/original/3X/1/8/18cbbaef00b77fe22a77a88283197360b86cfa05.jpeg)
2. Downloaded with filebeat
3. Opened "Visualise" in Kibana
4. Choose this "data.json file & Node = node1"
5. Choose "quantity of input messages"
6. Choose strange "Max"(for example)
7. Got great graph

But if I going to add second Node = node2 I have a trouble.  
I think I have tried all of the variants with interface but the desired result was not achieved...

Is it really possible to do it?  
Or I should parse source data file(with all the nodes and its data) into separate nodes files(so 1 file has data of only 1 node)? And play with Visualise interface?

The goal is to have a simple graph with lines(one parameter depending of time) of few nodes.

Could you help me, please?

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 22, 2020, 3:12am UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/2 "2020-11-22T03:12:30Z")

</div>

@avovana

What you're attempting to do is completely reasonable and I suspect you're very close to making it happen. Can you share the query you're attempting that is resulting in disappointment?

As best I understand, all you need to do is take your existing successful query and have it select an additional node value. Do you know what field type 'Node' is?

Thanks,  
Matt

---

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [November 24, 2020, 3:15pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/3 "2020-11-24T15:15:07Z")

</div>

Node is text.  
Some details about format:

```auto
{"Node": "feed_asts_ccy_securities", "Status": "online", "MsgIn": "0", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "17852", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "223144"}
{"Node": "feed_forts_instruments", "Status": "offline", "MsgIn": "0", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "17848", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "0"}
{"Node": "feed_micex_eqt_clr", "Status": "offline", "MsgIn": "0", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "21808", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "0"}
{"Node": "supervisor", "Status": "online", "MsgIn": "0", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "10613", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "0"}
{"Node": "transformer_asts_ccy", "Status": "online", "MsgIn": "1854", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "6705", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "1723"}
{"Node": "transformer_forts", "Status": "online", "MsgIn": "0", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "6698", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "0"}
{"Node": "transformer_micex", "Status": "online", "MsgIn": "0", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "6702", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "0"}
{"Node": "transport_asts_ccy", "Status": "online", "MsgIn": "1723", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "10656", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "1723"}
{"Node": "transport_asts_xml2", "Status": "online", "MsgIn": "109718", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "10657", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "10718"}
{"Node": "transport_forts", "Status": "online", "MsgIn": "0", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "10654", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "0"}
{"Node": "transport_micex", "Status": "online", "MsgIn": "0", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "10655", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "0"}
{"Node": "transport_micex_eqt", "Status": "online", "MsgIn": "0", "VER": "39e1e", "Timestamp": "2020-11-24T09:02:01.458902Z", "Warns": "0", "Pid": "10658", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "0"}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9e3a056a00546843a9c5f658787419698d96739f.png)

The desired result for 1 node:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/4/34be8e36745cd7fff1e917c57ccd74e4951ab0ca.png)

But what should I do next to have new line of the another Node here?

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 24, 2020, 4:16pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/4 "2020-11-24T16:16:19Z")

</div>

You need to aggregate on Node. If you load the ecommerce sample data you'll see a couple examples in the related dashboard.

---

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [November 25, 2020, 9:08am UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/5 "2020-11-25T09:08:43Z")

</div>

Matthew, thank you for a respond!

Unfortunately I didn't succeed...  
Kibana interface doesn't give me such opportunity in the "Aggregation" field.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/35f670df8a6a1eb6237890565b6eb26d46a10ece.png)

I deleted `and Node : "feed_forts_instruments` in a "Filters" field to have access to all of the Nodes in this log file.  
But even in this case "Node" is absent in the "Aggregation":

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6dbdfa23d12c97ba4ae28f6ebb1c12bbc5512fe5.png)

---

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [November 25, 2020, 12:42pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/6 "2020-11-25T12:42:37Z")

</div>

So I downloaded sample data with a [clue](https://logz.io/blog/elasticsearch-aggregations/)

> To get this sample data, visit your Kibana homepage and click on “Load a data set and a Kibana dashboard.” There, you will see the sample data provided for eCommerce orders and web logs.

Now I see that "Split Series" will lead me to success.  
In the sample data series splitted by text field "category"(with strange ".keyword" suffix):

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/7/57000c542b1c052b7939489f476336766c988e47.png)  
In my case "Node" has "text" format also(now I see why did you ask me to specify the format).  
But I can not choose it:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bc0d5a9317e938774ca97ee48ff01109c4cfdb66.png)

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 25, 2020, 3:15pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/7 "2020-11-25T15:15:20Z")

</div>

The terms aggregation works best with a `keyword` field type - [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html)

Note this text in the linked document - `In order to use it with text you will need to enable fielddata.`

---

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [November 26, 2020, 9:22am UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/8 "2020-11-26T09:22:45Z")

</div>

Thank you, Matthew!  
I see that I have 3 options:

1. 

> Set `fielddata=true` on [`your_field_name`] in order to load fielddata in memory by uninverting the inverted index.

2. 

> You can enable fielddata on an existing `text` field using the [PUT mapping API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html) as follows: PUT my-index-000001/\_mapping { "properties": { "my\_field": { "type": "text", "fielddata": true } } }

3. 

> Adding "keyword" type

**1.After some search I decided to change filebeat.yml and added `fielddata=true` to the `Node` field:**  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/3/6362d27a52bea19aaae6f61c9cd7318607d81251.png)

Reloaded filebeat.  
Reloaded indices.  
But don't see the result - "Node" was absent in a "Split Series".

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c2c1ef7430885c984901a15051592ac6ec3f98d.png)  
Removed this addition.

**2.After it I tried Dev Tools:**  
Firstly, tried to add `"keyword"`.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/a/ba7d9f8208bcd933ed856cf11de05d0a573f841e.png)

Secondly, made PUT with `fielddata=true`.  
Understood that one parameter was missed. Fixed. Got success:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73e3906584606f0199c087e0e01484a6f761d4f8.png)

Reload filebeat. Downloaded data. Again "Node" was absent:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e1dcbfb50cd7cb1cc9088ca951a255e5653a9809.png)  
Updated indices, check `"fielddata"`. It appeared:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/2/22a042e4754bab2d2c0b9b0354212311f38c6afa.png)  
But still "Node" was absent.  
Added data. Again "Node" was absent.

Thirdly, tried again with adding a `"keyword"`:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/6/567787d8b4fc9bfc9fa878c8bd29c835e6fb7dfc.png)

Updated indices. Made sure that result OK:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/8/78f655c6ae5eb3c4bd23639afb66c89fe1d7d91a.png)

Added data. Again "Node" was absent.

I suppouse the success is so close but can not get it...

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 27, 2020, 11:25pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/9 "2020-11-27T23:25:18Z")

</div>

Can you share the mapping for your index? It certainly looks to me like you did everything right, two different ways.

---

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [November 28, 2020, 5:18pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/10 "2020-11-28T17:18:19Z")

</div>

Thank you, Matthew!

Unfortunately, \*.txt is not allowed to attache...  
Can you give me your email via personal message if it possible.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [November 30, 2020, 3:07am UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/11 "2020-11-30T03:07:19Z")

</div>

Use [https://gist.github.com/](https://gist.github.com/)

---

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [November 30, 2020, 8:46am UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/12 "2020-11-30T08:46:45Z")

</div>

Unfortunately I have not access to it...

I got a successful upload here:  
[http://files.rsdn.org/133345/mapping.txt](http://files.rsdn.org/133345/mapping.txt)

A pretty complicated file. There is no "Node" mapping.

Another variant was made:  
In a fields.yml added filedata:

- name: Node  
type: text  
fielddata: true

So after reloading filebeat and elasticsearch can see new mapping in Kibana interface:

"Node": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/f/5f33f3c02404119658c792eadb16db73a41e6243.png)  
But again failure when try to select in a "Split Series":  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/7/173f89699e9a231c580108ec244f3154a28f0574.png)  
In a meantime I can select another field with the same mapping!  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/5/65ad731d39ded037a7e1288b7a60f956493cffa1.png)

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [December 6, 2020, 4:43am UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/13 "2020-12-06T04:43:03Z")

</div>

Hello @avovana,

Sorry for the delay.

The mapping certainly looks correct.

Is it possible for you to supply me with a few sample rows of data in csv format so I can attempt to reproduce? Obviously strip out any sensitive info.

Thanks,  
Matt

---

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [December 9, 2020, 8:45am UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/14 "2020-12-09T08:45:27Z")

</div>

@mattkime, thank you for a respond!  
It inspires me to go further)

```
Node,Status,MsgIn,VER,Warns,Pid,System,Errs,MsgOut
feed_asts_ccy_securities, online, 0, 39e1e, 0, 17852, MC_IFT_SBRF, 0, 223144
feed_micex, online, 0, 39e1e, 0, 17855, MC_IFT_SBRF, 2, 223155

```

=========================

I tried one more step with a field.  
Added field "Node1" with the type "keyword" in [filebeat.yml](http://files.rsdn.org/133345/filebeat.txt)  
I understood that I don't need "text" type with all of this difficulties to make it aggregatable. "keyword" is aggregatable by default.

For the first reload filebeat I saw "Node1" in kibana "Index managment", but now don't:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a0c54249c9d5c7b8837a9900c2941199bbc16d02.png)

But "Node1" is in the index pattern(and it is "Aggregatable"):

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73b3f4cb10f4534276f5bdb7cf85e4e31f4b4afd.png)  
(as a Node.keyword, though)

Added:  
`echo '{"Node": "descript", "Node1": "feed_micex", "Status": "online", "MsgIn": "0", "VER": "39e1e", "Warns": "0", "Pid": "17854", "System": "MC_IFT_SBRF", "Errs": "0", "MsgOut": "223155"}' > bla.json`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/6/669fdf8322c2d9bb01a884255731bc966457ae56.png)

Still can not choose:  
Node.keword  
Node1

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0c2bb40220826493d6551a369e6dc2aef818a54e.png)

P.S.  
By the way I noticed strange mapping. For example, "MsgIn" is "long" in a filebeat.yml, but in the "Index managment" in the "Mapping" is "text" as you can see on the picture above.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/f/2f13a1834becb5951badc011f5dcac329bd69833.png)  
Investigated that these 6 mapping conflicts related to all of my fields that are "long".

P.P.S  
After so many attempts now I want to start from scratch. All that I need is:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77e12cb16a9d27d6c8fcf5be9c483347b76b75df.png)  
But as I read I can not reload "Index pattern"( **filebeat-** \* in my case) because there are many indexed docs already ☹

I have an idea!  
Maybe make new?  
So, I will need to change my filebeat name:  
**filebeat** -new-7.8.1-2020.12.08-000118 -\> "smth1".  
Then modify filebeat.yml as I described above.  
And learn how to make new "Index pattern" for "smth1" and fill it with mapping.

---

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [December 9, 2020, 3:42pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/16 "2020-12-09T15:42:43Z")

</div>

Update.  
Deleted many previous indexes.

As I understood new one is created when new filebeat is started.  
Because I started and kill it a lot there were many indexes.

Made filebeat as I wanted:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/2/b2509b902ebe4ff60aea3bae8fb05dddda0ba5f3.png)

Started filebeat, new index was created with good mapping:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4eb4e57202052b43f397b1a9d572cbba09773502.png)

Conflicts dissapeared, types are good, Node is aggregatable:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/a/aa4176ba9464b437355ec7d971106d86fd276f5b.png)

Added to log 3 rows:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5de8da5f9109856270eaec050774f1908426d6ff.png)

Checked, the 1, 3 are good. The 2nd row was added badly somehow:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5a9db07e001f7cf1b0f49de14caea34d18d27cc9.png)

And you can guess the result in a "Split Series"...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/554c05169a9252a8f0819a90729334ce23e0fe45.png)  
The same sad story...  
I can not choose here the perfect suitable aggregatable "Node" ☹

---

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [December 12, 2020, 9:36am UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/17 "2020-12-12T09:36:08Z")

</div>

Maybe this update will help.  
Learned how to retrieve information:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c5b28bd8f2063e2c7261378e7fb65566bf65862e.png)

1.GET filebeat-7.8.1-2020.12.09-000001/\_doc/ **UoYdSHYBgrhx-iAPPOPp**

```auto
 {
  "_index" : "filebeat-7.8.1-2020.12.09-000001",
  "_type" : "_doc",
  "_id" : "UoYdSHYBgrhx-iAPPOPp",
  "_version" : 1,
  "_seq_no" : 2,
  "_primary_term" : 1,
  "found" : true,
  "_source" : {
    "@timestamp" : "2020-12-09T15:27:23.364Z",
    "Node" : "some_name",
    "MsgOut" : "223155",
    "Pid" : "17854",
    "Errs" : "0",
    "input" : {
      "type" : "log"
    },
    "System" : "MC_IFT_SBRF",
    "MsgIn" : "0",
    "Warns" : "0",
    "message" : "some_name",
    "VER" : "39e1e",
    "log" : {
      "offset" : 0,
      "file" : {
        "path" : "/home/mcift_pao/test_logs/bla.json"
      }
    },
    "agent" : {
      "hostname" : "algodev04.msk.trd.ru",
      "ephemeral_id" : "2f3c8f63-f2ba-41b6-80f0-1b15c12ab0b2",
      "id" : "4ef6de1d-c457-4179-88d0-d2a25770e29c",
      "name" : "algodev04.msk.trd.ru",
      "type" : "filebeat",
      "version" : "7.8.1"
    },
    "ecs" : {
      "version" : "1.5.0"
    },
    "Status" : "online",
    "host" : {
      "os" : {
        "codename" : "Maipo",
        "platform" : "rhel",
        "version" : "7.8 (Maipo)",
        "family" : "redhat",
        "name" : "Red Hat Enterprise Linux Server",
        "kernel" : "3.10.0-1127.19.1.el7.x86_64"
      },
      "id" : "0979853c5fc248359ccb2b6e9f67bd3e",
      "containerized" : false,
      "ip" : [
        "10.20.3.141",
        "fe80::250:56ff:fe9c:647c",
        "10.160.20.33",
        "fe80::250:56ff:fe9c:743c",
        "172.18.0.1",
        "172.20.0.1",
        "fe80::42:ceff:fe91:75c6",
        "fe80::fcef:f2ff:fe26:16a0"
      ],
      "name" : "algodev04.msk.trd.ru",
      "mac" : [
        "00:50:56:9c:64:7c",
        "00:50:56:9c:74:3c",
        "00:50:56:9c:44:c8",
        "02:42:a4:00:12:15",
        "02:42:ce:91:75:c6",
        "fe:ef:f2:26:16:a0"
      ],
      "hostname" : "algodev04.msk.trd.ru",
      "architecture" : "x86_64"
    }
  }
}

```

1. Learned how to make put:

```auto
POST /filebeat-7.8.1-2020.12.09-000001/_doc/1
{
  "Node": "feed_asts_ccy_securities",
  "Status": "online",
  "MsgIn": "0",
  "VER": "39e1e",
  "Warns": "0",
  "Pid": "17852",
  "System": "MC_IFT_SBRF",
  "Errs": "0",
  "MsgOut": "223144"
}

```

So I have:  
\_id = QIbmR3YBgrhx-iAPQ8\_t  
\_id = 9YYJSHYBgrhx-iAPPtt8  
\_id = UoYdSHYBgrhx-iAPPOPp  
\_id = 1

1. Tried to understand whether "Node" is aggregatable thanks to this request:

```auto
GET filebeat-7.8.1-2020.12.09-000001/_search
{
  "aggs": {
    "filebeat-7.8.1-2020.12.09-000001": {
       "terms" : { "field": "Node"}
    }
  }
}

```

Got:

> **Summary**
>
> ```auto
> {
> "took" : 2,
> "timed_out" : false,
> "_shards" : {
> "total" : 1,
> "successful" : 1,
> "skipped" : 0,
> "failed" : 0
> },
> "hits" : {
> "total" : {
> "value" : 4,
> "relation" : "eq"
> },
> "max_score" : 1.0,
> "hits" : [
> {
> "_index" : "filebeat-7.8.1-2020.12.09-000001",
> "_type" : "_doc",
> "_id" : "QIbmR3YBgrhx-iAPQ8_t",
> "_score" : 1.0,
> "_source" : {
> "@timestamp" : "2020-12-09T14:27:17.658Z",
> "log" : {
> "offset" : 0,
> "file" : {
> "path" : "/home/mcift_pao/test_logs/bla.json"
> }
> },
> "System" : "MC_IFT_SBRF",
> "Status" : "online",
> "MsgOut" : "223155",
> "Errs" : "0",
> "host" : {
> "ip" : [
> "10.20.3.141",
> "fe80::250:56ff:fe9c:647c",
> "10.160.20.33",
> "fe80::250:56ff:fe9c:743c",
> "172.18.0.1",
> "172.20.0.1",
> "fe80::42:ceff:fe91:75c6",
> "fe80::fcef:f2ff:fe26:16a0"
> ],
> "mac" : [
> "00:50:56:9c:64:7c",
> "00:50:56:9c:74:3c",
> "00:50:56:9c:44:c8",
> "02:42:a4:00:12:15",
> "02:42:ce:91:75:c6",
> "fe:ef:f2:26:16:a0"
> ],
> "name" : "algodev04.msk.trd.ru",
> "hostname" : "algodev04.msk.trd.ru",
> "architecture" : "x86_64",
> "os" : {
> "codename" : "Maipo",
> "platform" : "rhel",
> "version" : "7.8 (Maipo)",
> "family" : "redhat",
> "name" : "Red Hat Enterprise Linux Server",
> "kernel" : "3.10.0-1127.19.1.el7.x86_64"
> },
> "id" : "0979853c5fc248359ccb2b6e9f67bd3e",
> "containerized" : false
> },
> "message" : "feed_micex",
> "input" : {
> "type" : "log"
> },
> "Node" : "feed_micex",
> "Pid" : "17854",
> "MsgIn" : "0",
> "Warns" : "0",
> "VER" : "39e1e",
> "ecs" : {
> "version" : "1.5.0"
> },
> "agent" : {
> "ephemeral_id" : "2f3c8f63-f2ba-41b6-80f0-1b15c12ab0b2",
> "id" : "4ef6de1d-c457-4179-88d0-d2a25770e29c",
> "name" : "algodev04.msk.trd.ru",
> "type" : "filebeat",
> "version" : "7.8.1",
> "hostname" : "algodev04.msk.trd.ru"
> }
> }
> },
> {
> "_index" : "filebeat-7.8.1-2020.12.09-000001",
> "_type" : "_doc",
> "_id" : "9YYJSHYBgrhx-iAPPtt8",
> "_score" : 1.0,
> "_source" : {
> "@timestamp" : "2020-12-09T15:05:33.055Z",
> "host" : {
> "id" : "0979853c5fc248359ccb2b6e9f67bd3e",
> "containerized" : false,
> "ip" : [
> "10.20.3.141",
> "fe80::250:56ff:fe9c:647c",
> "10.160.20.33",
> "fe80::250:56ff:fe9c:743c",
> "172.18.0.1",
> "172.20.0.1",
> "fe80::42:ceff:fe91:75c6",
> "fe80::fcef:f2ff:fe26:16a0"
> ],
> "mac" : [
> "00:50:56:9c:64:7c",
> "00:50:56:9c:74:3c",
> "00:50:56:9c:44:c8",
> "02:42:a4:00:12:15",
> "02:42:ce:91:75:c6",
> "fe:ef:f2:26:16:a0"
> ],
> "name" : "algodev04.msk.trd.ru",
> "hostname" : "algodev04.msk.trd.ru",
> "architecture" : "x86_64",
> "os" : {
> "name" : "Red Hat Enterprise Linux Server",
> "kernel" : "3.10.0-1127.19.1.el7.x86_64",
> "codename" : "Maipo",
> "platform" : "rhel",
> "version" : "7.8 (Maipo)",
> "family" : "redhat"
> }
> },
> "agent" : {
> "name" : "algodev04.msk.trd.ru",
> "type" : "filebeat",
> "version" : "7.8.1",
> "hostname" : "algodev04.msk.trd.ru",
> "ephemeral_id" : "2f3c8f63-f2ba-41b6-80f0-1b15c12ab0b2",
> "id" : "4ef6de1d-c457-4179-88d0-d2a25770e29c"
> },
> "ecs" : {
> "version" : "1.5.0"
> },
> "log" : {
> "offset" : 161,
> "file" : {
> "path" : "/home/mcift_pao/test_logs/bla.json"
> }
> },
> "json" : { },
> "message" : "",
> "input" : {
> "type" : "log"
> }
> }
> },
> {
> "_index" : "filebeat-7.8.1-2020.12.09-000001",
> "_type" : "_doc",
> "_id" : "UoYdSHYBgrhx-iAPPOPp",
> "_score" : 1.0,
> "_source" : {
> "@timestamp" : "2020-12-09T15:27:23.364Z",
> "Node" : "some_name",
> "MsgOut" : "223155",
> "Pid" : "17854",
> "Errs" : "0",
> "input" : {
> "type" : "log"
> },
> "System" : "MC_IFT_SBRF",
> "MsgIn" : "0",
> "Warns" : "0",
> "message" : "some_name",
> "VER" : "39e1e",
> "log" : {
> "offset" : 0,
> "file" : {
> "path" : "/home/mcift_pao/test_logs/bla.json"
> }
> },
> "agent" : {
> "hostname" : "algodev04.msk.trd.ru",
> "ephemeral_id" : "2f3c8f63-f2ba-41b6-80f0-1b15c12ab0b2",
> "id" : "4ef6de1d-c457-4179-88d0-d2a25770e29c",
> "name" : "algodev04.msk.trd.ru",
> "type" : "filebeat",
> "version" : "7.8.1"
> },
> "ecs" : {
> "version" : "1.5.0"
> },
> "Status" : "online",
> "host" : {
> "os" : {
> "codename" : "Maipo",
> "platform" : "rhel",
> "version" : "7.8 (Maipo)",
> "family" : "redhat",
> "name" : "Red Hat Enterprise Linux Server",
> "kernel" : "3.10.0-1127.19.1.el7.x86_64"
> },
> "id" : "0979853c5fc248359ccb2b6e9f67bd3e",
> "containerized" : false,
> "ip" : [
> "10.20.3.141",
> "fe80::250:56ff:fe9c:647c",
> "10.160.20.33",
> "fe80::250:56ff:fe9c:743c",
> "172.18.0.1",
> "172.20.0.1",
> "fe80::42:ceff:fe91:75c6",
> "fe80::fcef:f2ff:fe26:16a0"
> ],
> "name" : "algodev04.msk.trd.ru",
> "mac" : [
> "00:50:56:9c:64:7c",
> "00:50:56:9c:74:3c",
> "00:50:56:9c:44:c8",
> "02:42:a4:00:12:15",
> "02:42:ce:91:75:c6",
> "fe:ef:f2:26:16:a0"
> ],
> "hostname" : "algodev04.msk.trd.ru",
> "architecture" : "x86_64"
> }
> }
> },
> {
> "_index" : "filebeat-7.8.1-2020.12.09-000001",
> "_type" : "_doc",
> "_id" : "1",
> "_score" : 1.0,
> "_source" : {
> "Node" : "feed_asts_ccy_securities",
> "Status" : "online",
> "MsgIn" : "0",
> "VER" : "39e1e",
> "Warns" : "0",
> "Pid" : "17852",
> "System" : "MC_IFT_SBRF",
> "Errs" : "0",
> "MsgOut" : "223144"
> }
> }
> ]
> },
> "aggregations" : {
> "filebeat-7.8.1-2020.12.09-000001" : {
> "doc_count_error_upper_bound" : 0,
> "sum_other_doc_count" : 0,
> "buckets" : [
> {
> "key" : "feed_asts_ccy_securities",
> "doc_count" : 1
> },
> {
> "key" : "feed_micex",
> "doc_count" : 1
> },
> {
> "key" : "some_name",
> "doc_count" : 1
> }
> ]
> }
> }
> }
> 
> ```

If the example is correct, it is!

The question is why I can not use this aggregatable "Node" in "Terms" in "Split Series" in "Visualization"?

---

<div class="post-metadata">

**Author:** ![avovana](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@avovana](https://discuss.elastic.co/u/avovana)\
**Post date:** [December 17, 2020, 12:17pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/18 "2020-12-17T12:17:47Z")

</div>

Good news from Graphana:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cdf90cd252c8c5dc22445ae759938a83dadd3282.png)

I can select it. And `it works !!!`

So, the problem is in the Kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2021, 12:17pm UTC](https://discuss.elastic.co/t/visualize-2-lines-2-nodes-with-1-parameter-per-time/256240/19 "2021-01-14T12:17:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
