# Aggregate / reformat search results from buckets into new fields

**URL:** <https://discuss.elastic.co/t/aggregate-reformat-search-results-from-buckets-into-new-fields/122240>\
**Category:** Elasticsearch\
**Created:** [March 2, 2018, 11:40am UTC](https://discuss.elastic.co/t/aggregate-reformat-search-results-from-buckets-into-new-fields/122240 "2018-03-02T11:40:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![vicpav](https://avatars.discourse-cdn.com/v4/letter/v/9de053/32.png) [@vicpav](https://discuss.elastic.co/u/vicpav)\
**Post date:** [March 2, 2018, 11:40am UTC](https://discuss.elastic.co/t/aggregate-reformat-search-results-from-buckets-into-new-fields/122240/1 "2018-03-02T11:40:13Z")

</div>

We are using ELK 5.6.8 and I am trying to setup search for a watcher that would periodically go through the logs and do the following:

1. search for a certain string in a field
2. aggregate the results per host
3. filter out the hosts in the bucket that have the count less than threshold
4. create the fields that contain  
a. the number of buckets  
b. content of the buckets formatted into a string

What I have so far:

```auto
GET my-logs-*/_search
{
  "query": {
    "bool": {
      "must": [
        { "query_string": { "fields": ["message_json.msg"], "query": "'something happened'"} }
      ],
      "filter": {
        "range": {
          "@timestamp": {
            "gt": "now-600m"
          }
        }
      }
    }
  },
  "aggregations": {
    "count_per_host": {
      "terms": {
        "field": "message_json.hostname.keyword",
        "order" : { "_count" : "desc" },
        "min_doc_count": 15
      }
    }
  }
}

```

and I get the result like that:

```auto
{
  "took": 82,
  "timed_out": false,
  "_shards": {
    "total": 99,
    "successful": 99,
    "skipped": 0,
    "failed": 0
  },
  "hits": {...},
  "aggregations": {
    "count_per_host": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": [
        {
          "key": "host-79gzj",
          "doc_count": 20
        },
        {
          "key": "host-gph59",
          "doc_count": 18
        }
      ]
    }
  }
}

```

But I could not figure out how to do the last aggregation to get the fields:

```auto
"hosts_number": 2 <- aggregations.count_per_host.buckets.length()
"hosts_string": "host-79gzj matched 20 times, host--gph59 matched 18 times"

```

I have a hunch that `script` should be used, but I cannot get it working with resulted buckets... 😞 Any ideas are very much appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2018, 11:40am UTC](https://discuss.elastic.co/t/aggregate-reformat-search-results-from-buckets-into-new-fields/122240/2 "2018-03-30T11:40:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
