# Visualize changes of an aggregation result over time

**URL:** <https://discuss.elastic.co/t/visualize-changes-of-an-aggregation-result-over-time/319897>\
**Category:** Kibana\
**Created:** [November 28, 2022, 1:14am UTC](https://discuss.elastic.co/t/visualize-changes-of-an-aggregation-result-over-time/319897 "2022-11-28T01:14:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![daverin](https://avatars.discourse-cdn.com/v4/letter/d/6a8cbe/32.png) [@daverin](https://discuss.elastic.co/u/daverin)\
**Post date:** [November 28, 2022, 1:14am UTC](https://discuss.elastic.co/t/visualize-changes-of-an-aggregation-result-over-time/319897/1 "2022-11-28T01:14:48Z")

</div>

Hi there.

I have been using Elastic for the past year but I am relatively new to Kibana.

**Basic info on my setup and usecase:**  
I have my database records streaming into Elastic via Kafka Connect. When a record changes in the db that record is updated in elastic. Each records has a unique identifier (which is used as the key in elastic), a status keyword field and a bunch of other source fields. The status field of records change (from "created" -\> "processing" -\> "failed").

**Question:**  
I am able to do aggregations using the current data in elastic at the point I run the query, but how do I see the result of those aggregations over time? In my case, I want to see a graph of how the amount of "processing" records has changed over time.

**Potential Solutions:**  
From [this video](https://www.youtube.com/watch?v=jFh5EWIVaSI&t=539s) I see that the data visualizer in ML anomaly detection gives me exactly what I want since it has to measure the change of aggregations. I expect though that there must be a more straightforward way to do this though. I feel like I'm missing something fundamental.

I could create a different index in which my key is based on time, essentially making it a log of my database. That way I don't lose any time series data, but then the issue is removing duplicate items from the queries. I'd need to group all the data by their unique identifier when visualizing.

I could also have a separate process that runs the an aggregation every X seconds and then dumps that result to a new index.

* * *

Any would be greatly appreciated 🙌🏾

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 28, 2022, 6:34am UTC](https://discuss.elastic.co/t/visualize-changes-of-an-aggregation-result-over-time/319897/2 "2022-11-28T06:34:33Z")

</div>

Hi @daverin Welcome to the community!

Perhaps take a look at transforms

> **[Transforming data | Elasticsearch Guide \[8.5\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/transforms.html)**

---

<div class="post-metadata">

**Author:** ![daverin](https://avatars.discourse-cdn.com/v4/letter/d/6a8cbe/32.png) [@daverin](https://discuss.elastic.co/u/daverin)\
**Post date:** [November 28, 2022, 7:53pm UTC](https://discuss.elastic.co/t/visualize-changes-of-an-aggregation-result-over-time/319897/3 "2022-11-28T19:53:48Z")

</div>

Thank you @stephenb ! This is exactly what I was looking for.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2022, 7:54pm UTC](https://discuss.elastic.co/t/visualize-changes-of-an-aggregation-result-over-time/319897/4 "2022-12-26T19:54:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
