# Visualizing Weekly Data Changes in Kibana

**URL:** <https://discuss.elastic.co/t/visualizing-weekly-data-changes-in-kibana/383038>\
**Category:** Kibana\
**Tags:** visualisation\
**Created:** [October 28, 2025, 7:51am UTC](https://discuss.elastic.co/t/visualizing-weekly-data-changes-in-kibana/383038 "2025-10-28T07:51:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MaximeBon](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@MaximeBon](https://discuss.elastic.co/u/MaximeBon)\
**Post date:** [October 28, 2025, 7:51am UTC](https://discuss.elastic.co/t/visualizing-weekly-data-changes-in-kibana/383038/1 "2025-10-28T07:51:58Z")

</div>

Hello everyone,

I am a cybersecurity engineer utilizing Elasticsearch to analyze vulnerabilities detected within my systems. Every week, I import a list of newly detected vulnerabilities into my Elasticsearch index, including essential fields such as the CVE (the vulnerability ID) and the @timestamp (the date of import).

I aim to create a graph in Kibana that visually represents the differences week-over-week regarding new and missing vulnerabilities. Specifically, I would like to track:

- **New CVEs** that appear for the first time in the current week compared to the previous week, along with the exact list of these CVEs.

- **Missing CVEs** that were present in the previous week but are absent in the current week, including their exact identifiers.

I am having trouble visualizing this data effectively. Could anyone provide guidance or examples on how to achieve this in Kibana? Any advice on creating the necessary aggregations or using visualizations to represent this detailed data would be greatly appreciated.

Thank you in advance for your help!

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [October 28, 2025, 9:20am UTC](https://discuss.elastic.co/t/visualizing-weekly-data-changes-in-kibana/383038/2 "2025-10-28T09:20:37Z")

</div>

Hello @MaximeBon

Just a thought to understand if below view can be the start & if you are looking / thinking for a different view which can help to streamline the view :

if we use unique count of records for CVE with @timestamp field with minimum Interval as 1 week ,  
last week null , this week 1 means new CVE  
last week 1 , this week null means missing CVE  
if last week 1 , this week 1 means CVE found last week & this week

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c5c77d6fde11d077f254fbf2a8b35d63f45868a2.png)

Thanks!!

---

<div class="post-metadata">

**Author:** ![MaximeBon](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@MaximeBon](https://discuss.elastic.co/u/MaximeBon)\
**Post date:** [October 28, 2025, 3:38pm UTC](https://discuss.elastic.co/t/visualizing-weekly-data-changes-in-kibana/383038/3 "2025-10-28T15:38:57Z")

</div>

Hello @Tortoise

This view can clearly be the start of what I'm looking for !

I would like to capture the variation for each entry so I can identify both the new CVEs and those that are missing. My ultimate goal is to represent this data in two bar charts: one for the count of new CVEs and another for the count of missing CVEs for each week.

---

<div class="post-metadata">

**Author:** ![MaximeBon](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@MaximeBon](https://discuss.elastic.co/u/MaximeBon)\
**Post date:** [November 12, 2025, 7:36am UTC](https://discuss.elastic.co/t/visualizing-weekly-data-changes-in-kibana/383038/4 "2025-11-12T07:36:38Z")

</div>

Hello everyone,

I wanted to update you on the issue I was facing regarding tracking new and missing CVEs in Kibana. I’ve found a solution that I believe will help anyone in a similar situation.

To monitor the weekly variations of CVEs effectively, we can use the following techniques:

1. **Using the `differences()` Function**:

2. **Tracking Individual CVEs** :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e28736511efe9129fa3aa1b7fdf7a93c70f26a2d.png)

### **Visualization**

For the visual representation, I recommend creating two bar charts:

- One for the count of **new CVEs** : `pick_max(differences(count()),0)`

- Another for the count of **missing CVEs** : `pick_min(differences(count()),0)`

Thank you for your initial suggestion!
