# Visualize data from multiple indexes in one chart

**URL:** <https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262>\
**Category:** Kibana\
**Created:** [April 2, 2020, 5:54pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262 "2020-04-02T17:54:06Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [April 2, 2020, 5:54pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/1 "2020-04-02T17:54:06Z")

</div>

Hi, I have 5-7 indexes with different names and want to create one chart which will get a field that is existing in all indexes. For example index 1, index 2, index3, have a field called "type" and I want to get the count of "type" in all indexes in Kibana's visualize app. I do not want to combine all indexes into one index, as I want to see the sepearte index names.

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [April 2, 2020, 6:08pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/2 "2020-04-02T18:08:31Z")

</div>

Hi @Mehak_Bhargava,

Each visualization works on one index pattern, you can group index patterns by wild card like: index1, index2, index3, ...etc can have index pattern: index\*. However seems like you want to see each index separately, so the other option is to create a visualization for each index pattern and add them to one dashboard. Hope this helps.

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [April 2, 2020, 6:22pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/3 "2020-04-02T18:22:57Z")

</div>

Hi @LizaD, thanks for replying!  
For index pattern, I am not sure if it will work because my index1 is called obapi, index2 is called rmmserver, and index3 is called dispatcher with all different names. Since they dont have similarity in naming, can one index pattern still be created for them? Because then I could make it work with my charts!

If not, is there a way that I can make a chart based on a field called type for instance, that occurs in all these three indexes? So aggregation will be solely based on field name!

I read this post which discussed that as long as I have field name same- "type" I can create a series?

> [@How to plot multiple series by multiple indexes into one visualization?](https://discuss.elastic.co/t/how-to-plot-multiple-series-by-multiple-indexes-into-one-visualization/93872/2):
>
> in the panel settings of time series visual builder you can override the index pattern. you can even set it to \* (to look at all index patterns). the only requirement is that all your index patterns have the same time field (for example @timestamp). then you can plot metrics on fields from different indexes. you could also do the same using timelion, without the restriction of same time field: .es(index=myfirstindex, timefield=timestamp, metric=sum:bytes), .es(index=secondindex, timefield=tim…

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [April 2, 2020, 7:42pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/4 "2020-04-02T19:42:08Z")

</div>

Hi @Mehak_Bhargava,

Yes that is correct you can use time series visual builder on multiple index patterns, as yes in your case, the wildcard won't work since the names don't share a substring.  
Hope that helps, give it a try and let us know. Thanks!

Liza

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [April 2, 2020, 7:50pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/5 "2020-04-02T19:50:05Z")

</div>

The documentation for time series visualization for kibana 7.4 version isnt available. Is that still a feature?

Also, why do I have empty lines in kibana under under my index? Had to use a picture here to explain properly

 ![emptylinespace.jpg](https://us1.discourse-cdn.com/elastic/original/3X/3/9/39dfb66f5e920a52797c729584d2671f9afa1a76.png)

Please explain or suggest where should I look ino to resolve this.

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [April 2, 2020, 9:21pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/6 "2020-04-02T21:21:28Z")

</div>

Hi @Mehak_Bhargava,

Yes it should be available but it was renamed to TSVB in version 7.3.0 🙂 so please see guide here:  
[https://www.elastic.co/guide/en/kibana/7.4/TSVB.html](https://www.elastic.co/guide/en/kibana/7.4/TSVB.html)

Do you mean the lines showing as '-' I believe that means no data is returned for that date/time for that field, can you confirm whether you do have data and it is not showing?

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [April 2, 2020, 9:32pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/7 "2020-04-02T21:32:31Z")

</div>

Hi @LizaD, thank you for documentation. Let me get back to you on how it works out so others know it too.

And yes, I do have data. I have a file called dispatcher-adapter-quartz.logs and it has data and it appears in fields I have selected. But same again few lines above, it wont show data. if all data is read, does it send the "-" then? As you see below, timestamp and loglevel is extracted for the same file at below but not in above lines.

 ![emptyspace2](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f79e828ec6d5a079ef653b53ac0a1633cb45530f.png)

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [April 3, 2020, 3:28am UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/8 "2020-04-03T03:28:37Z")

</div>

Hi @Mehak_Bhargava,

Thanks please do let us know how TSVB works out or if you have any questions.

On the discover question, I checked some of my data and when I see the dash present it is on fields that are not applicable, when I traced back that data in Kibana to the source it matched in that those fields are not applicable.

Check your source data and mappings to see what the difference is between the events showing fields and the ones not showing fields. If there is data missing can you give me the sample source correlated.

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [April 3, 2020, 6:10pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/9 "2020-04-03T18:10:44Z")

</div>

Hi @LizaD,

I got a chart where loglevel of all indexes are present. But As you see on the right hand side, the ledger has repetitive field like "INFO" and "INFO". One INFO has 3529 count but other INFO has 0. Why do we have repetitions?  
I understand why "INFO" and "info'" will be repeated. but can I not mention that "INFO"= "info" so there is no repetition? And also remove the WARN =0 and INFO =0? And, I do have some loglevel under DEBUG, so I am not sure why that is showing 0 as well?

 ![TSVB](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a0132c3234d3264c58c0fd6e45b6d6216abfe4ac.png)

I traced the "-" and found that when the files on server havent updated, then these "-" comes in. For example, my dispacter.log was last updated on April 2nd, so after the logs were groked and fields displayed until April 2nd, the discover shows "-" from until last time file updated till now. I understand that this log aggregation is always looking for real time files but shouldnt there be a better way in discover to only show when files were updated and not show "-" when file isn't updated? Please suggest a permanent solution for it.

A temporary solution would be to remove the "@timestamp" from the step where we create the index pattern so the logs will be mapped to whenever data comes, right?

Thanks,  
Mehak

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [April 6, 2020, 6:42pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/10 "2020-04-06T18:42:54Z")

</div>

Thanks @Mehak_Bhargava, let me see if someone from our visualization team can help answer.

@flash1293 can you help?

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [April 7, 2020, 6:10pm UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/11 "2020-04-07T18:10:25Z")

</div>

Hi @LizaD and @flash1293, could you suggest how to remove the '-' empty lines or fix the replicates found in ledger of TSVB?

Thanks,  
Mehak

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [April 8, 2020, 8:19am UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/12 "2020-04-08T08:19:33Z")

</div>

In both Discover and TSVB you should be able to use a filter to filter those documents out:  
the KQL query `yourFieldName : *`filters down to the documents that have the field `yourFieldName` set. I'm not sure whether the field is actually empty in your case or whether it just contains a `-` symbol. In the latter case you can filter it out using `NOT yourFieldName: '-'`

In TSVB you can set the filter in the `Options` tab of the series:

 ![Screenshot 2020-04-08 at 10.17.18](https://us1.discourse-cdn.com/elastic/original/3X/7/f/7faed652b4b82eccf805331a54ecfda50d483ce2.png)

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [April 21, 2020, 12:31am UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/13 "2020-04-21T00:31:15Z")

</div>

Thanks @flash1293, this helped!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2020, 12:31am UTC](https://discuss.elastic.co/t/visualize-data-from-multiple-indexes-in-one-chart/226262/14 "2020-05-19T00:31:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
