# Greylog ReSt for Barchart

**URL:** <https://community.graylog.org/t/greylog-rest-for-barchart/26276>\
**Category:** Graylog Central (peer support)\
**Tags:** curl, dashboards\
**Created:** [October 24, 2022, 4:41pm UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276 "2022-10-24T16:41:03Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![gianluca-valentini](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gianluca-valentini/32/1592_2.png) [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Post date:** [October 24, 2022, 4:41pm UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/1 "2022-10-24T16:41:03Z")

</div>

Hi,  
using Graylog 4.3.7 i’d like to get the same data coming from Stream bar chart

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/899988373f2e513f1d8ab7f59a90e57d1ff478a7.png)

What is the correct ReST that I should use to have the same aggregated values?  
Thanks  
Gianluca

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 24, 2022, 10:46pm UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/2 "2022-10-24T22:46:33Z")

</div>

Hey @gianluca-valentini

If I understand you correct, The metric from the bar chart you want the API?

---

<div class="post-metadata">

**Author:** ![gianluca-valentini](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gianluca-valentini/32/1592_2.png) [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Post date:** [October 25, 2022, 4:22am UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/3 "2022-10-25T04:22:11Z")

</div>

Hi @gsmith  
Yes. The api that i should use to have the same bar chart that we can see on the stream.

Thanks a lot

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 25, 2022, 4:23am UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/4 "2022-10-25T04:23:50Z")

</div>

hey,

Good question, I’m unsure 😆.  
I would need to check out the API browser on Graylog, or have you done that already?

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 25, 2022, 4:33am UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/5 "2022-10-25T04:33:15Z")

</div>

Hey,

I looked though my personal docs & I found this, not sure it will help

```auto
http://graylog.domain.com:9000/api/dashboards/5ca714037efa22464e1de773/widgets/c8ceaf4c-4816-4fb8-9b1c-063ac3b0fcc8/value

```

---

<div class="post-metadata">

**Author:** ![gianluca-valentini](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gianluca-valentini/32/1592_2.png) [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Post date:** [October 25, 2022, 4:42am UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/6 "2022-10-25T04:42:00Z")

</div>

Thanks.  
There should be something where you can specify the aggregation period (week, day, month and so on), the range, in order to have the data utile to have the same view 🤔 with that filters (stream Id too)

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 25, 2022, 4:54am UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/7 "2022-10-25T04:54:58Z")

</div>

If the API does not work you can extract this out of MongoDb using

```auto
mongoexport -u mongo_admin -p password123 --collection=views --db=graylog --out=/var/log/dashboard.json

```

That puts it into a file , OR

```auto
mongoexport -u mongo_admin -p password123 --collection=views --db=graylog --pretty

```

---

<div class="post-metadata">

**Author:** ![gianluca-valentini](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gianluca-valentini/32/1592_2.png) [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Post date:** [October 25, 2022, 5:04am UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/8 "2022-10-25T05:04:57Z")

</div>

Ok thanks 👍  
But is that a result that should change on incoming messages?  
I will try as you suggest  
Thanks

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 25, 2022, 5:12am UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/9 "2022-10-25T05:12:33Z")

</div>

So my script looks like this,

```auto
[graylog_user@graylog server]$ cat mongo.sh
#!/usr/bin/expect -f
        

        spawn mongoexport -u mongo_admin -p primalFear1967 --collection=traffic --db=graylog --out=/var/log/traffic.json

        spawn mongoexport -u mongo_admin -p password --collection=views --db=graylog --out=/var/log/dashboard.json

        spawn mongoexport -u mongo_admin -p password --collection=alerts --db=graylog --out=/var/log/events.json

        spawn mongoexport -u mongo_admin -p password --collection=streams --db=graylog --out=/var/log/streams/streams-$date.json
  expect eof
[graylog_user@graylog server]$

```

Connected to Cron

Widget from that ( before and after )

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/166692be0a0700bb054c030878705ac03ce2e1ae.png)

---

<div class="post-metadata">

**Author:** ![gianluca-valentini](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gianluca-valentini/32/1592_2.png) [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Post date:** [October 25, 2022, 10:37am UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/10 "2022-10-25T10:37:32Z")

</div>

Thanks.  
My sceario required something like rest api request with the response that I need to show like stream histogram.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/b/b4348ce172169afa36cdd5bf7bdf7872c0920870.png)  
I don’t address that using exported file as I have to filter using stream value

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 25, 2022, 9:45pm UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/11 "2022-10-25T21:45:25Z")

</div>

Only other thing I can think of is using the views/dashboards API,

```auto
https://graylog.domain.com:9000/api/views?page=1&per_page=50&sort=title&order=asc

```

That does give me a list of widget on that dashboard with the correct UID. not sure about stats what you want.

```auto
{
      "id": "61b1431428b37319e15ade65",
      "type": "DASHBOARD",
      "title": " Statistics ",
      "summary": " Statistics ",
      "description": " Statistics ",
      "search_id": "6350d441a8dd061f01244e40",
      "properties": [],
      "requires": {},
      "state": {
        "00000170-0e12-5080-8bf5-00155d601d11": {
          "selected_fields": null,
          "static_message_list_id": null,
          "titles": {
            "widget": {              
              "f968cfa9-63be-425f-a55a-a63b875d98a1": "All Messages",
              "2d7d372b-7593-423d-8f74-bef9a942692e": "WARNING",
              "c876fb0e-1bcf-448b-9a34-5e2871578325": "Messages for SourceModuleName:forum",
              "73430375-b0e1-4d2d-991e-e677227efff9": "Windows Failed Logon",
              "49493dfe-431e-4ecf-afd9-be43adc66d51": "count by SourceModuleName",
              "b40aea9d-e844-42c6-9bf7-2ee8df499b87": "Messages for stream_oids:62ff051e1e4cd17f63e69c53",            
              "a208d975-3b32-4972-ba00-d670867239fa": "Messages for service:X\\-WINDOWS",            
              "f5d240d8-8dca-464d-8e2c-83d2d369af2c": "Successful logon",
              "b8da22b5-f872-4e0e-9124-ce242bd8db20": "count by source",
              "8455868d-65e6-44b9-bd9c-a4d29d28f28b": "Messages for SourceModuleName:streams",
              "0782a354-5f62-4cb2-a9f3-b16b56ccbd5b": "Count by IP",
              "663cd66d-bf84-4946-adee-09e88ce30553": "Messages for SourceModuleName:traffic",
              "20631aeb-f950-4865-b2e0-5f4551dc5f9f": "Messages for SourceModuleName:mail",
              "4473dceb-3a5c-48fd-ad4b-538619920454": "Event Status",

```

My apologies, I don’t use API very much, I use Grafana & Prometheus //w Graylog it makes life a little easier.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [November 8, 2022, 9:45pm UTC](https://community.graylog.org/t/greylog-rest-for-barchart/26276/12 "2022-11-08T21:45:48Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
