SingleStat value set by field within elk document

Hello all,
I am newer to grafana so this might be a silly question that I am just missing. I am trying to have a SingleStat panel (within grafana) display the value of a field from a ELK document. I would like to map the SingleStat value to the number found within the field “Exptime”. I can get my grafana SingleStat to display the count of documents sent but I need it to display the last documents value of “Exptime”. Is this possible?

Document from ELK: (I cleaned out hostnames and IP’s :-).
"_index": “health-2018.02.26”,
"_type": “health”,
"_id": “AWHThA6R6_mj73XdkMJy”,
"_version": 1,
"_score": null,
"_source": {
“severity”: “notice”,
“ldaphost”: “MYHOSTNAME”,
“programname”: “ldap-check”,
“procid”: “-”,
“message”: " LDAPCERT, STATUS=ERROR, Expire=47, ldaphost=MYHOSTNAME",
“type”: “health”,
“tags”: [
"@timestamp": “2018-02-26T19:08:21.000Z”,
"@version": “1”,
“host”: “MYIPADDRESS”,
“sysloghost”: “MYHOSTNAME”,
“facility”: “user”,
“Exptime”: “47”
“fields”: {
"@timestamp": [
“highlight”: {
“programname”: [
“message”: [
" @kibana-highlighted-field@LDAPCERT@/kibana-highlighted-field@, STATUS=ERROR, Expire=47, ldaphost=MYHOSTNAME"
“sort”: [


You need to use an aggregate function, like max, which will return the max of Exptime in your example per interval. Then you select the Stat=Current in options tab.

I imagine a query similar to this example would work for you:


Thank you for the reply. I went down that road this morning which lead us to this:

  1. Add int to the grok filter to bring that value in as a integer
    example: %{WORD}=%{NUMBER:Exptime:int}
  2. Reset the index in ELK (delete index and allow it to re add its self)
  3. In grafana singlestat set metric to Extended Stats -> Exptime -> Stats: Min
  4. refresh the panel and BAM your data is there.

I was just missing the grok bring in Exptime as a integer.

Thank you for your help. Have a good day.

1 Like