Guide
Create a Bar Chart in Kibana Lens from an Elasticsearch Index Pattern
Learn how to build a bar chart in Kibana Lens from an Elasticsearch index pattern, with step‑by‑step steps, limits, and common pitfalls.
Published by Tasadduq Burney
16 Nov 2025, 05:57 UTC
3 min148.2K views0

Quick answer
In Kibana Lens you can build a bar chart of HTTP status codes by dragging the http.status field to the Split series bucket and keeping the default Metric as Count.
Step‑by‑step configuration
- Open Kibana and go to Stack Management → Index Patterns. Confirm that an index pattern such as
logstash-*exists and lists thehttp.statusfield. - Navigate to Visualize → Lens → Add to start a new visualization.
- In the data panel, locate the
http.statusfield (usually under the chosen index pattern). Drag it to the Buckets → Split series area. - Leave the Metric panel set to
Count(the default aggregation). - Click Apply. Lens builds a terms aggregation on
http.statusand renders a bar chart where each bar corresponds to a status code. - Press Save, give the visualization a name, choose the appropriate Space, and confirm.
How Lens builds the chart
Lens translates the drag‑and‑drop actions into an Elasticsearch aggregation request. The Split series bucket becomes a terms aggregation on the keyword sub‑field of http.status. The Metric bucket stays as a count aggregation. The response returns buckets keyed by status code and their document counts, which Lens renders as vertical bars.
Limits and things to watch
- Lens only supports aggregations that match the visualization type. For a bar chart you can use terms, histogram, date histogram, or range aggregations on the bucket axis; custom Painless scripts are not available in the bucket configuration.
- High‑cardinality fields (e.g.,
request.url) can cause the terms aggregation to return thousands of buckets, leading to slow queries or timeouts. Limit the split to a low‑cardinality field or add a filter to reduce the dataset. - Lens visualizations are saved as Kibana saved objects. Moving them between clusters requires exporting the JSON (
Management → Saved Objects → Export) and importing on the target cluster; version mismatches may break the visualization. - If you add new fields to the underlying index after creating the index pattern, you must refresh the pattern (
Stack Management → Index Patterns → Refresh field list) before Lens shows them.
Common mistakes
- Saving the visualization to the wrong Space, which hides it from teammates who do not have access to that Space.
- Expecting Lens to display scripted fields defined in Kibana without reindexing; scripted fields are only available if they are mapped in Elasticsearch or defined as runtime fields.
- Leaving the Metric as something other than Count (e.g., Sum) when you actually want a frequency chart, resulting in unexpected values.
- Ignoring the query bar at the top of Lens; a stray filter can unintentionally narrow the data and produce an empty chart.
Verification steps
- Open Kibana, go to Stack Management → Index Patterns and verify the pattern shows
http.status. - In Visualize → Lens, add a new visualization, drag
http.statusto Split series, keep Metric as Count, click Apply and confirm a bar chart appears. - Check the browser developer console for no error messages and ensure the network request to Elasticsearch returns HTTP 200 with an aggregation payload.
- Save the visualization to a Space, create a new dashboard, add the saved visualization, and verify it renders for other users with access to that Space.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.