# Visualize arrays of values over time

**URL:** <https://discuss.elastic.co/t/visualize-arrays-of-values-over-time/89033>\
**Category:** Kibana\
**Created:** [June 12, 2017, 11:58am UTC](https://discuss.elastic.co/t/visualize-arrays-of-values-over-time/89033 "2017-06-12T11:58:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![smlbiobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smlbiobot/32/29622_2.png) [@smlbiobot](https://discuss.elastic.co/u/smlbiobot)\
**Post date:** [June 12, 2017, 11:58am UTC](https://discuss.elastic.co/t/visualize-arrays-of-values-over-time/89033/1 "2017-06-12T11:58:18Z")

</div>

I am trying to visualize the change of values over time with fields that are stored inside another field.

I don’t know how to explain this using text so I will show you a screenshot of my data here and perhaps you can help me better:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/b/a/ba3ac8fe076e75ad853a6934220b988aa84f3937.png)

Originally I created a single field called roles which has all the role names / ids / counts grouped together but ES complains that objects are not well supported and that’s why I turn them into 3 arrays instead.

That said, I don’t know how I might show the value of a role over time. What I need: the count changes overtime for each role\_name. My work around right now is that I dynamically created a ton of fields:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/9/7/972e2c1554513aeae609166b3dbcb326bc1fd447.png)

and now I am able to track them overtime / use it in the Metric visualization. But as you can see this gets pretty bad as the number of fields I have just increased exponentially.

Can you help?

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [June 12, 2017, 5:16pm UTC](https://discuss.elastic.co/t/visualize-arrays-of-values-over-time/89033/2 "2017-06-12T17:16:03Z")

</div>

I recommend adjusting your data ingestion so it separates this information into individual fields and documents. If you can index each tuple as a separate document, with fields `role_name`, `role_id`, `role_count` and `timestamp`, this then becomes easy to visualize, and you can filter by `role_name:Battle-Bay` to narrow down to a single role.

---

<div class="post-metadata">

**Author:** ![smlbiobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smlbiobot/32/29622_2.png) [@smlbiobot](https://discuss.elastic.co/u/smlbiobot)\
**Post date:** [June 12, 2017, 9:16pm UTC](https://discuss.elastic.co/t/visualize-arrays-of-values-over-time/89033/3 "2017-06-12T21:16:38Z")

</div>

Interesting… but I don’t really know how to do that. Right now the library I use just send everything via logstash using this config:

```
input {
    udp {
        port => 5959
        codec => json
    }
}
output {
    elasticsearch {
        hosts => ["localhost:9200"]
    }
    stdout {
        codec => rubydebug
    }
}

```

these then get sent to logstash-\* — I don’t actually know this well enough to create documents.

This is the library I am using btw: [https://pypi.python.org/pypi/python-logstash](https://pypi.python.org/pypi/python-logstash) — I need to use Python to send data via logstash to ES. Or are you suggesting that I communicate directly to ES? If so, what would you suggest that I do? Please point me to the necessary documentation if possible.

Should I in fact just skip logstash and use this instead: [https://www.elastic.co/guide/en/elasticsearch/client/python-api/current/index.html](https://www.elastic.co/guide/en/elasticsearch/client/python-api/current/index.html)

Much appreciated!

---

<div class="post-metadata">

**Author:** ![smlbiobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smlbiobot/32/29622_2.png) [@smlbiobot](https://discuss.elastic.co/u/smlbiobot)\
**Post date:** [June 12, 2017, 9:53pm UTC](https://discuss.elastic.co/t/visualize-arrays-of-values-over-time/89033/4 "2017-06-12T21:53:40Z")

</div>

You know what, never mind… I was wondering why it previously complained and it won‘t let me model things the way I wanted to. But I just did a test run and this seems to be working right now:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b5d28e69e2c186021bc932578ab3ae0147122a98.png)

Previously when I did this though it complains and said that field data cannot be an object…

---

<div class="post-metadata">

**Author:** ![smlbiobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smlbiobot/32/29622_2.png) [@smlbiobot](https://discuss.elastic.co/u/smlbiobot)\
**Post date:** [June 12, 2017, 9:59pm UTC](https://discuss.elastic.co/t/visualize-arrays-of-values-over-time/89033/5 "2017-06-12T21:59:37Z")

</div>

@Stacey_Gammon oops but wait… while it didn’t complain about the object, how can I grab those values in this visualize graph type:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/1/01a3695ab09696d977f53d60100179dc90547820.png)

Coz the field is not a number and it doesn’t show up in the dropdown list.

That btw was why I did what I did… just to get it to show up…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2017, 9:59pm UTC](https://discuss.elastic.co/t/visualize-arrays-of-values-over-time/89033/6 "2017-07-10T21:59:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
