# Aggregate sum child documents' cumulative data while keeping some of parent's source fields

**URL:** <https://discuss.elastic.co/t/aggregate-sum-child-documents-cumulative-data-while-keeping-some-of-parents-source-fields/252907>\
**Category:** Elasticsearch\
**Created:** [October 21, 2020, 10:28pm UTC](https://discuss.elastic.co/t/aggregate-sum-child-documents-cumulative-data-while-keeping-some-of-parents-source-fields/252907 "2020-10-21T22:28:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rfferrao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rfferrao/32/76344_2.png) [@rfferrao](https://discuss.elastic.co/u/rfferrao)\
**Post date:** [October 21, 2020, 10:28pm UTC](https://discuss.elastic.co/t/aggregate-sum-child-documents-cumulative-data-while-keeping-some-of-parents-source-fields/252907/1 "2020-10-21T22:28:27Z")

</div>

I'd like to know if it's possible to do this. Let's say I have the following mapping for a `testindex`:

```auto
{
	"properties": {
		"datetime": {
			"type": "date"
		},
		"datetime_range": {
			"type": "date_range"
		},
		"devname": {
			"type": "keyword"
		},
		"group": {
			"type": "keyword"
		},
		"my_join_field": {
			"type": "join",
			"eager_global_ordinals": true,
			"relations": {
				"startevent": "traffic"
			}
		},
		"new_rcvdbyte": {
			"type": "long"
		},
		"new_sentbyte": {
			"type": "long"
		},
		"rcvdbyte": {
			"type": "long"
		},
		"sentbyte": {
			"type": "long"
		},
		"tunnelid": {
			"type": "keyword"
		},
		"user": {
			"type": "keyword"
		}
	}
}

```

Which contains the following sample documents:

```auto
[{
	"user": "someuser",
	"devname": "somedevice",
	"datetime_range": {
		"gte": "2020-10-21T15:50:57",
		"lte": "2020-10-21T16:50:57"
	},
	"my_join_field": "startevent"
},
{
	"user": "someuser",
	"group": "somegroup",
	"devname": "somedevice",
	"datetime": "2020-10-21T15:52:57",
	"sentbyte": 123,
	"rcvdbyte": 456,
	"new_sentbyte": 123,
	"new_rcvdbyte": 456,
	"my_join_field": {
		"name": "traffic",
		"parent": "1"
	}
},
{
	"user": "someuser",
	"group": "somegroup",
	"devname": "somedevice",
	"datetime": "2020-10-21T15:54:57",
	"sentbyte": 246,
	"rcvdbyte": 912,
	"new_sentbyte": 123,
	"new_rcvdbyte": 456,
	"my_join_field": {
		"name": "traffic",
		"parent": "1"
}]

```

I'd like to be able to aggregate these documents such that the output resembles something like this:

```auto
{
	"user" : "someuser",
	"devname" : "somedevice",
	"datetime_range" : {
		"gte" : "2020-10-21T15:50:57",
		"lte" : "2020-10-21T16:50:57"
	},
	"group": "somegroup",
	"new_sentbyte_sum": 246,
	"new_rcvdbyte_sum": 912
}

```

The most I could come up with was using `inner_hits` within `has_child`, but this doesn't take care of the `sum` that I need for both `new_rcvdbyte` and `new_sentbyte` fields contained in the child documents.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2020, 10:28pm UTC](https://discuss.elastic.co/t/aggregate-sum-child-documents-cumulative-data-while-keeping-some-of-parents-source-fields/252907/2 "2020-11-18T22:28:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
