如何使用Kibana Timelion绘制无聚合的原始时间序列?
Hey Daniel, nice to tackle this with you! Plotting raw time series data (no sums, averages, or other aggregations—just the exact values of a field from every document over time) in Timelion is totally doable with a simple tweak to the core .es() function. Here's how to pull it off:
Core Syntax to Disable Aggregation
Timelion defaults to aggregating data, but you can bypass this using the metric=raw parameter in the .es() function. This tells Timelion to fetch every individual value of your target field instead of rolling them up.
Here’s the basic structure:
.es(index=YOUR_INDEX_NAME, metric=raw, field=YOUR_TARGET_FIELD)
Customize Time Field (If Needed)
If your index uses a non-default time field (not @timestamp), specify it with the timefield parameter:
.es(index=YOUR_INDEX_NAME, metric=raw, field=YOUR_TARGET_FIELD, timefield=YOUR_TIME_FIELD)
Just pick your desired time window using Timelion’s built-in time picker—you’ve already got that covered, which is perfect.
Optional: Adjust Visualization Style
Raw data can look cluttered depending on your dataset, so you can tweak how it displays:
- Use
.points()to show individual data markers:.es(index=sensor_readings, metric=raw, field=voltage).points(size=2, fill=1) - Use
.lines()to connect points (great for seeing trends in dense data):.es(index=sensor_readings, metric=raw, field=voltage).lines(width=1)
Quick Notes to Avoid Headaches
- Make sure your time field is mapped as a date type in Elasticsearch—Timelion needs this to sort data correctly over time.
- This works best for numeric fields (temperature, voltage, etc.). String fields can’t be plotted as a time series directly.
- As you mentioned, stick to a reasonable time window if you have a lot of data—too many points can slow down the visualization.
Example in Action
Let’s say you have an index weather_station with time field recorded_at and a field humidity you want to plot raw. Your query would be:
.es(index=weather_station, metric=raw, field=humidity, timefield=recorded_at).points()
This will plot every single humidity reading exactly as it was recorded, ordered by time.
内容的提问来源于stack exchange,提问作者Daniel

