# Aggregate data after month to get smaller index

**URL:** <https://discuss.elastic.co/t/aggregate-data-after-month-to-get-smaller-index/155941>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [November 8, 2018, 5:27pm UTC](https://discuss.elastic.co/t/aggregate-data-after-month-to-get-smaller-index/155941 "2018-11-08T17:27:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [November 8, 2018, 5:27pm UTC](https://discuss.elastic.co/t/aggregate-data-after-month-to-get-smaller-index/155941/1 "2018-11-08T17:27:36Z")

</div>

hi all,  
I would like to have a method to aggregate informations collected using Metricbeat.  
Currently I have the `system` module enabled that collects details every 30 seconds. this situation is really good if I want to monitor information, for instance, of the current day or yesterday.

If I would like to store informations older than 6 months, what should be the best approach? I mean, if I would like to see the CPU trend of the last year, I think that my granularity should not be so deeper (30 seconds) but maybe hourly.  
obviously, using Kibana and choosing the time range of 6 months it will adapts the dashboard but in my index there still will be a lot of documents (catched every 30 seconds). so, is there any operation that could I perform to make the index more tiny?

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [November 8, 2018, 8:09pm UTC](https://discuss.elastic.co/t/aggregate-data-after-month-to-get-smaller-index/155941/2 "2018-11-08T20:09:26Z")

</div>

It sounds like you’re looking for Elasticsearch’s Rollups feature.

> **[Data Rollups in Elasticsearch: You Know, for Saving Space
	  	 | Elastic](https://www.elastic.co/blog/data-rollups-in-elasticsearch-you-know-for-saving-space)**
>
> This post is part of the Elastic{ON} 2018 blog series where we recap specific demos and related deep-dive sessions from the conference. From machine learning forecasting to APM to secur...

[https://www.elastic.co/guide/en/elasticsearch/reference/current/xpack-rollup.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/xpack-rollup.html)

---

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [November 9, 2018, 2:52pm UTC](https://discuss.elastic.co/t/aggregate-data-after-month-to-get-smaller-index/155941/3 "2018-11-09T14:52:15Z")

</div>

really thank you for the answer that addressed me in the correct direction.  
I have just one doubt: how can I roll up every field that exists in my original index? Should I specify all of them in my rollup job?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2018, 2:52pm UTC](https://discuss.elastic.co/t/aggregate-data-after-month-to-get-smaller-index/155941/4 "2018-12-07T14:52:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
