# Visualize value change over time in table

**URL:** <https://discuss.elastic.co/t/visualize-value-change-over-time-in-table/133555>\
**Category:** Kibana\
**Created:** [May 28, 2018, 1:58pm UTC](https://discuss.elastic.co/t/visualize-value-change-over-time-in-table/133555 "2018-05-28T13:58:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thomas\_Schneider](https://avatars.discourse-cdn.com/v4/letter/t/85f322/32.png) [@Thomas\_Schneider](https://discuss.elastic.co/u/Thomas_Schneider)\
**Post date:** [May 28, 2018, 1:58pm UTC](https://discuss.elastic.co/t/visualize-value-change-over-time-in-table/133555/1 "2018-05-28T13:58:11Z")

</div>

Hi,

I am trying to visualize the change of a field over time. (stupid beginner, sorry)

I am currently sending each hour a message from ~1000 devices with y unipue ID in each message

```
{
    	"DIAG": {
    		"Name": "Device_1",
    		"Value": "636119"
    	}
    }

```

Sometime the value will be changed, e.g.:  
**But only sometimes - the most of the message are identically.**

```
{
	"DIAG": {
		"Name": "Device_1",
		"Value": "636111"
	}
}

```

What i am create is a simple list to displsy the change of "Value".

- deviceID
- ChangeTime
- OldValue
- NewValue  
(over all devices)

Or also be possible a table with **two** lines:

- deviceID
- timeTime
- Value

==\> Have anyone a idea? 🙂

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [May 29, 2018, 11:31pm UTC](https://discuss.elastic.co/t/visualize-value-change-over-time-in-table/133555/2 "2018-05-29T23:31:42Z")

</div>

You will want to also record the timestamp of when the metric was calculated.

Here is the sample data and mapping I created as an example to work from:

```auto
PUT discuss-133555
{
  "mappings": {
    "doc": {
      "properties": {
        "DIAG": {
          "properties": {
            "Name": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            },
            "Value": {
              "type": "integer"
            },
            "@timestamp": {
              "type": "date"
            }
          }
        }
      }
    }
  }
}

POST discuss-133555/doc
{
  "DIAG": {
    "Name": "Device_1",
    "Value": 100,
    "@timestamp": "2018-03-12T09:21:31"
  }
}

POST discuss-133555/doc
{
  "DIAG": {
    "Name": "Device_1",
    "Value": 200,
    "@timestamp": "2018-03-13T09:21:31"
  }
}

POST discuss-133555/doc
{
  "DIAG": {
    "Name": "Device_1",
    "Value": 300,
    "@timestamp": "2018-03-14T09:21:31"
  }
}

POST discuss-133555/doc
{
  "DIAG": {
    "Name": "Device_2",
    "Value": 30,
    "@timestamp": "2018-03-12T09:21:31"
  }
}

POST discuss-133555/doc
{
  "DIAG": {
    "Name": "Device_2",
    "Value": 40,
    "@timestamp": "2018-03-13T09:21:31"
  }
}

POST discuss-133555/doc
{
  "DIAG": {
    "Name": "Device_2",
    "Value": 50,
    "@timestamp": "2018-03-14T09:21:31"
  }
}

```

Here the value is something like disk space used. In order to graph the rate of change, I can use a derivative function to calculate the rate of change.

 ![20](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d73b6fd5c525c979e05a7b8900994c7595ac8162.png)

I then bucket it over time, and split on DIAG.Name:

 ![26](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1c9b5e967bc67df76402fb270518c5bb436ed88f.png)

This will then show me the rate of change, which is 10 per day for device\_2 and 100 for device\_1.

 ![44](https://us1.discourse-cdn.com/elastic/original/3X/d/e/de5d2c9896aa87ada727bab8df90cc63bf02b3f7.png)

Hopefully this helps.

---

<div class="post-metadata">

**Author:** ![Thomas\_Schneider](https://avatars.discourse-cdn.com/v4/letter/t/85f322/32.png) [@Thomas\_Schneider](https://discuss.elastic.co/u/Thomas_Schneider)\
**Post date:** [June 13, 2018, 5:44am UTC](https://discuss.elastic.co/t/visualize-value-change-over-time-in-table/133555/3 "2018-06-13T05:44:07Z")

</div>

Hi,

sorry for the late response and thanks a lot for your reply.

Yes, the timestamp is also stored in the message.

I am looking more for a table instead of a graph and just want to visualize the last changes of this value.

The most of the time a value from one device is the same like before. But sometime this value will be changed.

```
POST discuss-133555/doc
{
  "DIAG": {
    "Name": "Device_1",
    "Value": 100,
    "@timestamp": "2018-03-12T09:21:31"
  }
}

POST discuss-133555/doc
{
  "DIAG": {
    "Name": "Device_1",
    "Value": 100,
    "@timestamp": "2018-03-13T09:21:31"
  }
}

POST discuss-133555/doc
{
  "DIAG": {
    "Name": "Device_1",
    "Value": 200,
    "@timestamp": "2018-03-14T09:21:31"
  }
}

POST discuss-133555/doc
{
  "DIAG": {
    "Name": "Device_1",
    "Value": 200,
    "@timestamp": "2018-03-15T09:21:31"
  }
}

```

i am lookling for a result like this in a table:

Device | NewValue | OldValue | Change  
Device\_1 | 200 | 100 | 2018-03-14T09:21:31

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2018, 5:44am UTC](https://discuss.elastic.co/t/visualize-value-change-over-time-in-table/133555/4 "2018-07-11T05:44:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
