# Want to make dashboards from my structured data

**URL:** <https://discuss.elastic.co/t/want-to-make-dashboards-from-my-structured-data/375494>\
**Category:** Elastic Observability\
**Created:** [March 6, 2025, 4:26am UTC](https://discuss.elastic.co/t/want-to-make-dashboards-from-my-structured-data/375494 "2025-03-06T04:26:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Journald-user](https://avatars.discourse-cdn.com/v4/letter/j/a88e57/32.png) [@Journald-user](https://discuss.elastic.co/u/Journald-user)\
**Post date:** [March 6, 2025, 4:26am UTC](https://discuss.elastic.co/t/want-to-make-dashboards-from-my-structured-data/375494/1 "2025-03-06T04:26:11Z")

</div>

I am trying to use Elasticsearch/Kibana as a replacement for my InfluxDB/Grafana setup.

I have structured data being sent to my elasticsearch instance using the journald plugin (systemctl logs in json format).

This data has a field on it called "total"

I want to take the aggregate of the "total" field over time across all logs.

How do I do this?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [March 6, 2025, 9:51am UTC](https://discuss.elastic.co/t/want-to-make-dashboards-from-my-structured-data/375494/2 "2025-03-06T09:51:15Z")

</div>

Hi @Journald-user,

You can do this by creating a [Lens visualization](https://www.elastic.co/guide/en/kibana/current/lens.html) in your dashboard, with the sum formula over the `total` field, similar to the below:

 ![Screenshot 2025-03-06 at 09.46.14](https://us1.discourse-cdn.com/elastic/original/3X/b/0/b062184ec180876cf0db223c4300a6855ebf064e.jpeg)

Hope that helps!

---

<div class="post-metadata">

**Author:** ![Journald-user](https://avatars.discourse-cdn.com/v4/letter/j/a88e57/32.png) [@Journald-user](https://discuss.elastic.co/u/Journald-user)\
**Post date:** [March 6, 2025, 3:26pm UTC](https://discuss.elastic.co/t/want-to-make-dashboards-from-my-structured-data/375494/3 "2025-03-06T15:26:33Z")

</div>

My structured data is not being indexed in the "event" parsing view, so I can't select the total field like you show. Here is an example of one of the entire logs being send to Kibana as viewed in the discover tab:

```auto
{"timestamp":"2025-03-06T15:11:19Z","service":"tracker","total":5,"total_failed":1}

```

and here is exploring all fields with "event" in them

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/1/21bf9a6ed6f195ea3a1da800795088014eaa1eea.png)

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [March 6, 2025, 3:49pm UTC](https://discuss.elastic.co/t/want-to-make-dashboards-from-my-structured-data/375494/4 "2025-03-06T15:49:39Z")

</div>

Thanks for the additional context @Journald-user. Do you have an available data view sitting on top of the event logs that you see in discover? Is that the data view that your field listing is for?

---

<div class="post-metadata">

**Author:** ![Journald-user](https://avatars.discourse-cdn.com/v4/letter/j/a88e57/32.png) [@Journald-user](https://discuss.elastic.co/u/Journald-user)\
**Post date:** [March 6, 2025, 4:10pm UTC](https://discuss.elastic.co/t/want-to-make-dashboards-from-my-structured-data/375494/5 "2025-03-06T16:10:30Z")

</div>

I do not think so

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/2508fb21bef1acd7a187a2f0bba10d693039f565.png)

I have not done anything to support structured data so far. I am simply feeding in structured data using the journald integration.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [March 7, 2025, 9:55am UTC](https://discuss.elastic.co/t/want-to-make-dashboards-from-my-structured-data/375494/6 "2025-03-07T09:55:51Z")

</div>

Thanks for confirming. @Journald-user can you confirm that you have data available for the selected timerange and that the data view pattern matches these logs?

---

<div class="post-metadata">

**Author:** ![Journald-user](https://avatars.discourse-cdn.com/v4/letter/j/a88e57/32.png) [@Journald-user](https://discuss.elastic.co/u/Journald-user)\
**Post date:** [March 7, 2025, 5:17pm UTC](https://discuss.elastic.co/t/want-to-make-dashboards-from-my-structured-data/375494/7 "2025-03-07T17:17:21Z")

</div>

Hi, yes the data is visible and I can make generic charts like a bar chart for the message count. The problem is that the structured data is not being parsed by Kibana. It just sees the logs as logs. It doesn't seem to be doing anything to parse data out of the logs. Here is a screenshot showing that Elasticsearch, Kibana, and Lens all see the logs, but the structured data within the logs is not being parsed. Is what I am trying to do even possible?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/d/ad55a7079c1751f9c5ca56d7ec38ff528333b718.png)
