[Elasticsearch-UI][Watcher] Threshold graph in watcher scale is not accurate #34157
Labels
bug
Fixes for quality problems that affect the customer experience
Feature:Watcher
Team:Kibana Management
Dev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more
Kibana version: 6.6.0
Elasticsearch version: 6.6.0
Server OS version: Mac 10.14.3
Browser version: Chrome 73.0.3683.86 (Official Build) (64-bit)
Browser OS version: Mac 10.14.3
Original install method (e.g. download page, yum, from source, etc.): tar.gz
Describe the bug: When creating a threshold alert in watcher, the scale on the graph in the GUI does not match the actual events from the same query against Elasticsearch. Both examples below are 5 second buckets.
Steps to reproduce:
Expected behavior: The graph in the Threshold watch should have a similar event count as seen in Discover. You can see from the images below, each using logstash* as the index pattern (this was the ONLY logstash feed going into the cluster) that the Discover app shows on average 300,000 documents per 5 second bucket while the graph in the Threshold Watcher UI shows around 70,000 documents per 5 second bucket.
Screenshots (if relevant):
Errors in browser console (if relevant): N/A
Provide logs and/or server output (if relevant): See above screen shots.
Any additional context: The graph in watcher doesn't make it easy to choose an accurate starting point to create a threshold watch as is.
The text was updated successfully, but these errors were encountered: