# Aggregate Query Results

**URL:** <https://discuss.elastic.co/t/aggregate-query-results/276570>\
**Category:** Elasticsearch\
**Created:** [June 21, 2021, 6:09pm UTC](https://discuss.elastic.co/t/aggregate-query-results/276570 "2021-06-21T18:09:27Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![usman1](https://avatars.discourse-cdn.com/v4/letter/u/c67d28/32.png) [@usman1](https://discuss.elastic.co/u/usman1)\
**Post date:** [June 21, 2021, 6:09pm UTC](https://discuss.elastic.co/t/aggregate-query-results/276570/1 "2021-06-21T18:09:27Z")

</div>

I am fetching timestamp and data against that timestamp with my search query to Elasticsearch node. The result being fetched contains multiple values against the same timeframe and I want Elasticsearch to return the aggregated value instead of single values.

For instance, the returned data array looks similar to following:  
`Time: ['2020-10-04 12:28','2020-10-04 12:28','2020-10-04 12:28','2020-10-04 12:29','2020-10-04 12:29'....]`  
`Vals: [10,10,10,10,10]`

I want it to aggregate Vals with respect to Time and the result should look like following:  
`Time: ['2020-10-04 12:28','2020-10-04 12:29',....]`  
`Vals: [30,20]`

Currently my query is following:

```auto
GET _search
{
  "query": {
    "bool": {
      		"must": [
        	{
          		"match": {
            		"B_ID": "348"
          		}
        	},
        	{
          		"match": {
            		"FLAG": "SCALE"
          		}
        	}
      		]
    	}
  },
   "aggs": {
    "AG_PPM": { "sum": { "field": "PPM" } }
  },
  "fields": [
    "PPM",
    "TIMESTAMP"
  ],
  "_source": false
}

```

But this does not seems to work and I am only getting the requested fields (PPM, TIMESTAMP) only.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 22, 2021, 7:56am UTC](https://discuss.elastic.co/t/aggregate-query-results/276570/2 "2021-06-22T07:56:24Z")

</div>

Please provide a fully reproducible example. This question is impossible to answer without a lot of guesswork, because we are missing the document structure. So please provide an example including index creation/mapping, sample documents and the query, this would help a lot!

Thank you!

---

<div class="post-metadata">

**Author:** ![usman1](https://avatars.discourse-cdn.com/v4/letter/u/c67d28/32.png) [@usman1](https://discuss.elastic.co/u/usman1)\
**Post date:** [June 22, 2021, 9:25am UTC](https://discuss.elastic.co/t/aggregate-query-results/276570/3 "2021-06-22T09:25:58Z")

</div>

@spinscale Complete response of the above mentioned query can be found [here.](https://pastebin.com/MxuGnjy8) It can be seen that the PPMs are aggregated at the end but that aggregation is applied on all the fetched records. I want this aggregation applied on the results for which Timestamp is same.

Kindly let me know if there is still something which I should explain.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 22, 2021, 9:30am UTC](https://discuss.elastic.co/t/aggregate-query-results/276570/4 "2021-06-22T09:30:18Z")

</div>

Try a date histogram, that contains the sum aggregation within. Sounds like that could help in your case.

---

<div class="post-metadata">

**Author:** ![usman1](https://avatars.discourse-cdn.com/v4/letter/u/c67d28/32.png) [@usman1](https://discuss.elastic.co/u/usman1)\
**Post date:** [June 22, 2021, 10:25am UTC](https://discuss.elastic.co/t/aggregate-query-results/276570/5 "2021-06-22T10:25:59Z")

</div>

@spinscale Thanks for the help. Can you please direct me to a sample query/solution which can help me in knowing the syntax for that?

---

<div class="post-metadata">

**Author:** ![amitkr](https://avatars.discourse-cdn.com/v4/letter/a/e19b73/32.png) [@amitkr](https://discuss.elastic.co/u/amitkr)\
**Post date:** [June 22, 2021, 10:39am UTC](https://discuss.elastic.co/t/aggregate-query-results/276570/6 "2021-06-22T10:39:15Z")

</div>

Hi,  
you can use something like this one.

```auto
  "aggs": {
    "AG_PPM": {
      "date_histogram": {
        "field": "TIMESTAMP",
        "fixed_interval": "1m"
      },
      "aggs": {
        "count": {
          "sum": {
            "field": "PPM"
          }
        }
      }
    }
  }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2021, 10:40am UTC](https://discuss.elastic.co/t/aggregate-query-results/276570/7 "2021-07-20T10:40:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
