# Visualize two time series with nested objects

**URL:** <https://discuss.elastic.co/t/visualize-two-time-series-with-nested-objects/284171>\
**Category:** Kibana\
**Created:** [September 14, 2021, 9:55am UTC](https://discuss.elastic.co/t/visualize-two-time-series-with-nested-objects/284171 "2021-09-14T09:55:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![maccn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maccn/32/77268_2.png) [@maccn](https://discuss.elastic.co/u/maccn)\
**Post date:** [September 14, 2021, 9:55am UTC](https://discuss.elastic.co/t/visualize-two-time-series-with-nested-objects/284171/1 "2021-09-14T09:55:30Z")

</div>

Hello everyone,

I am trying to visualize two time series in Kibana reading the data from Elasticsearch.  
The structure of my document is the following:

```auto
{
  "sensorName": "Sensor1",
  "values": [
    {
      "feature": {
        "key": "feature1",
        "value": 67
      }
    },
    {
      "feature": {
        "key": "feature2",
        "value": 15
      }
    }
  ],
  "timestamp": 1631519919904
}

```

I want to visualize one time series for the values in the first element of the array (the one with “key”=“feature1”) and another time series for the second element of the array (“key”=“feature2”).

I tried the following query in KQL:

```auto
values.feature:{key:"feature1"} 

```

But I got a visualization error:

```auto
[esaggs] > values.feature.key is not a nested field but is in nested group "values.feature" in the KQL expression.

```

How can I fix the visualization?

Thank you for your help.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [September 14, 2021, 12:40pm UTC](https://discuss.elastic.co/t/visualize-two-time-series-with-nested-objects/284171/2 "2021-09-14T12:40:55Z")

</div>

Hello @maccn

I think this might be relevant - [Kibana Query Language | Kibana Guide [7.15] | Elastic](https://www.elastic.co/guide/en/kibana/7.15/kuery-query.html#_nested_field_queries)

Whats the mapping for this index?

---

<div class="post-metadata">

**Author:** ![maccn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maccn/32/77268_2.png) [@maccn](https://discuss.elastic.co/u/maccn)\
**Post date:** [September 14, 2021, 1:48pm UTC](https://discuss.elastic.co/t/visualize-two-time-series-with-nested-objects/284171/3 "2021-09-14T13:48:00Z")

</div>

Thank you for your answer. I tried to change my query in:

```auto
values:{feature.key: "feature1" }

```

But I got a similar error:

```auto
[esaggs] > values.feature.key is not a nested field but is in nested group "values" in the KQL expression.

```

The mapping for the index is:

```auto
{
  "topic-sensor" : {
    "mappings" : {
      "properties" : {
        "timestamp" : {
          "type" : "date"
        },
        "values" : {
          "properties" : {
            "feature" : {
              "properties" : {
                "key" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "value" : {
                  "type" : "float"
                }
              }
            }
          }
        },
        "sensorName" : {
          "type" : "text",
          "fields" : {
            "keyword" : {
              "type" : "keyword",
              "ignore_above" : 256
            }
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [September 14, 2021, 3:10pm UTC](https://discuss.elastic.co/t/visualize-two-time-series-with-nested-objects/284171/4 "2021-09-14T15:10:36Z")

</div>

> [@maccn](#):
>
> I want to visualize one time series for the values in the first element of the array (the one with “key”=“feature1”) and another time series for the second element of the array (“key”=“feature2”).

If possible, this would likely be easier if you could denormalize your data. Instead of having both array elements in the same doc, put them in different docs.

You mention using nested fields but thats not shown in the mapping - [Nested field type | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/nested.html#nested-fields-array-objects)

It looks like you data is indexed as object types - [Object field type | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/object.html)

---

<div class="post-metadata">

**Author:** ![maccn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maccn/32/77268_2.png) [@maccn](https://discuss.elastic.co/u/maccn)\
**Post date:** [September 14, 2021, 8:45pm UTC](https://discuss.elastic.co/t/visualize-two-time-series-with-nested-objects/284171/5 "2021-09-14T20:45:41Z")

</div>

Unfortunately, I can't denormalize the data. Is there another solution to obtain what I want?

Moreover, I thought that "values" is the nested field and the element of the array are the objects, am I wrong?

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [September 14, 2021, 9:02pm UTC](https://discuss.elastic.co/t/visualize-two-time-series-with-nested-objects/284171/6 "2021-09-14T21:02:52Z")

</div>

It might be worthwhile to create a new index to test queries against.

> Moreover, I thought that "values" is the nested field and the element of the array are the objects, am I wrong?

This seems like a reasonable expectation but its not confirmed by the mapping. I'd like to see `values` be marked as type `nested`.

---

<div class="post-metadata">

**Author:** ![maccn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maccn/32/77268_2.png) [@maccn](https://discuss.elastic.co/u/maccn)\
**Post date:** [September 15, 2021, 9:18am UTC](https://discuss.elastic.co/t/visualize-two-time-series-with-nested-objects/284171/7 "2021-09-15T09:18:40Z")

</div>

I tried to create a new index on a different instance of Elasticsearch with the following mapping:

```auto
PUT /topic-sensor
{
  "mappings" : {
    "properties" : {
      "timestamp" : {
        "type" : "date"
      },
      "values" : {
        "type": "nested", 
        "properties" : {
          "feature" : {
            "properties" : {
              "key" : {
                "type" : "text"
              },
              "value" : {
                "type" : "float"
              }
            }
          }
        }
      },
      "sensorName" : {
        "type" : "text"
      }
    }
  }
}

```

Now, when I try to create a visualization, I can't choose any field in the Aggregation if I select the Average operation. The error is the following:

```auto
The index pattern topic-sensor does not contain any of the following compatible field types: number or histogram

```

But, in the search bar, Kibana suggests me the correct field (like in the example on the documentation):

```auto
values:{ feature.key : "feature1"}

```

It seems that the query will work but the field values.feature.value is not visible for the aggregation operation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2021, 9:19am UTC](https://discuss.elastic.co/t/visualize-two-time-series-with-nested-objects/284171/8 "2021-10-13T09:19:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
