# Aggregate push\_previous\_map\_as\_event seems not work

**URL:** <https://discuss.elastic.co/t/aggregate-push-previous-map-as-event-seems-not-work/114498>\
**Category:** Logstash\
**Created:** [January 8, 2018, 10:44am UTC](https://discuss.elastic.co/t/aggregate-push-previous-map-as-event-seems-not-work/114498 "2018-01-08T10:44:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rayburn](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@Rayburn](https://discuss.elastic.co/u/Rayburn)\
**Post date:** [January 8, 2018, 10:44am UTC](https://discuss.elastic.co/t/aggregate-push-previous-map-as-event-seems-not-work/114498/1 "2018-01-08T10:44:41Z")

</div>

I followed the sample 4# of logstash aggregation guide which url is [https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate-example4](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate-example4)  
The log output json is right, data have been aggregated , but nothing happen in elasticsearch, no index created. Does anyone encounter this occurrence either? Is this a bug to aggregate filter plugin? I doubt whether "aggregate push\_previous\_map\_as\_event =\> true" is worked.  
Logstash is the newest version which is 6.1.1

---

<div class="post-metadata">

**Author:** ![Rayburn](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@Rayburn](https://discuss.elastic.co/u/Rayburn)\
**Post date:** [January 9, 2018, 8:55am UTC](https://discuss.elastic.co/t/aggregate-push-previous-map-as-event-seems-not-work/114498/2 "2018-01-09T08:55:27Z")

</div>

I have figured out this issue by myself. Cause I index multiple types and use type condition to insure the input data to specific elasticsearch index, like

> output {  
> if([type] == "town\_info") {  
> elasticsearch {  
> hosts =\> "192.168.5.100:9200"  
> index =\> "town\_info"  
> document\_type =\> "data"  
> template =\> "/home/es/logstash-6.1.1/conf/aggregation/town\_template.json"  
> template\_name =\> "town\_template.json"  
> template\_overwrite =\> true  
> }  
> }  
> stdout {  
> codec =\> json\_lines  
> }  
> }

But in the sample 4#, the original event has been cancelled. Therefore the "type" didn't get from the input configuration. In the "aggregate" section "map" has been instead of event, So I assign the "type" value to map, like

> aggregate {  
> task\_id =\> "%{country\_name}"  
> code =\> "  
> map['country\_name'] = event.get('country\_name')  
> map['type'] = event.get('type')  
> map['towns'] ||=   
> map['towns'] \<\< {'town\_name' =\> event.get('town\_name')}  
> event.cancel()  
> "  
> push\_previous\_map\_as\_event =\> true  
> timeout =\> 3  
> }

Then it works. But the blemish is there will be a field named "type" in this type index. Does anybody can tell me how to do it perfect!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2018, 8:56am UTC](https://discuss.elastic.co/t/aggregate-push-previous-map-as-event-seems-not-work/114498/3 "2018-02-06T08:56:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
