如何在Kibana中创建按指定Job汇总Core/Memory的时间轴仪表盘
Got it, let's walk through exactly how to get this done step by step—first aggregating your Core/Memory data by job, then building the time-based dashboard in Kibana.
We'll use Kibana's built-in tools to calculate summed (or averaged, maxed, etc.) values for Core/Memory grouped by your Job name, with time on the X-axis.
Option 1: Line Chart (Best for Time-Based Trends)
This is ideal if you want to track how resource usage changes over time per job:
- Open Kibana, head to the Visualize Library, click Create visualization, and pick Line from the options.
- Select your target index pattern (the one holding your Core/Memory/Job log data) as the data source.
- Configure the X-Axis:
- Choose Date Histogram as the aggregation type.
- Select your time field (most likely
@timestampif using standard ELK logging, or your custom time field). - Set the time interval (Hourly, Daily, etc.—match it to your log ingestion frequency).
- Configure the Y-Axis:
- Pick Sum (or Avg/Max/Min, depending on your definition of "汇总") as the aggregation type.
- Select either the
CoreorMemoryfield as the target metric.
- Add a job grouping:
- Click Add → Split Series.
- Choose Terms as the aggregation type.
- Select your Job name field (the third red column you mentioned).
- Adjust the Size setting to show the top N jobs (set to 0 to display all jobs).
- Hit Update—you’ll see a line chart with time on the X-axis, resource totals on the Y-axis, and a separate line for each job.
Option 2: Bar Chart (Great for Side-by-Side Job Comparisons)
If you prefer categorical comparisons over trend lines, follow the same steps above but start by selecting Bar instead of Line. The X/Y axis and job grouping settings are identical—you’ll just get bar clusters per time interval instead of lines.
Once you have your Core and Memory visualizations ready, assemble them into a dashboard:
- Go to Kibana’s Dashboard page, click Create dashboard.
- Click Add, then select the visualizations you just created (you can add both Core and Memory charts to the same dashboard).
- Resize and rearrange the charts to fit your layout. Use the top-right time picker to narrow down the date range you want to view.
- Click Save, give your dashboard a descriptive name (like "Job Resource Usage Over Time"), and you’re done—you can access it anytime from the Dashboard library.
- If your Job names have inconsistent formatting (e.g., "JobA" vs "joba"), add a Lowercase pipeline to the Job field in your index pattern to normalize values before aggregating.
- For a more intuitive drag-and-drop experience, try using Kibana’s Lens tool instead of classic visualizations. Just drag your time field to the X-axis, Job field to the color/series dimension, and Core/Memory to the Y-axis with a Sum aggregation—Lens handles the rest automatically.
- Double-check that your index pattern includes all three fields (Core, Memory, Job). If they’re missing, refresh the index pattern or re-create it to pick up the new fields.
内容的提问来源于stack exchange,提问作者Frank

