# Aggregating by hour

**URL:** <https://discuss.elastic.co/t/aggregating-by-hour/18522>\
**Category:** Elasticsearch\
**Created:** [July 8, 2014, 8:06am UTC](https://discuss.elastic.co/t/aggregating-by-hour/18522 "2014-07-08T08:06:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jenny\_Blunt](https://avatars.discourse-cdn.com/v4/letter/j/96bed5/32.png) [@Jenny\_Blunt](https://discuss.elastic.co/u/Jenny_Blunt)\
**Post date:** [July 8, 2014, 8:06am UTC](https://discuss.elastic.co/t/aggregating-by-hour/18522/1 "2014-07-08T08:06:01Z")

</div>

I was sort of expecting the following to give me an aggregation which  
groups the results only by hour:

curl [http://localhost:9000/stream/\_search](http://localhost:9000/stream/_search) -d '{  
"aggs" : {  
"visitor\_count" : { "date\_histogram" : { "field" : "created\_at", "interval" : "hour"} }  
}  
}'

As it stands, it does group by hour, but it's also grouped by day. (I end  
up with 24 results for each day I have data).

I understand this is correct however, I would like to understand how it  
possible to group this only by the hour so I have 24 results only?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/cd84375c-2fbc-48c3-b1cd-79f04e89d6a2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/cd84375c-2fbc-48c3-b1cd-79f04e89d6a2%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Gabe\_Gorelick\_Feldma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabe_gorelick_feldma/32/1423_2.png) [@Gabe\_Gorelick\_Feldma](https://discuss.elastic.co/u/Gabe_Gorelick_Feldma)\
**Post date:** [July 8, 2014, 6:19pm UTC](https://discuss.elastic.co/t/aggregating-by-hour/18522/2 "2014-07-08T18:19:58Z")

</div>

I think you want something like a histogram with a value script to decide  
the bucket. But it looks like histogram doesn't support that, so would a  
range agg work? Otherwise, it might be easiest to store the hour in  
addition to the timestamp.

On Tuesday, July 8, 2014 4:06:02 AM UTC-4, Jenny Blunt wrote:

> I was sort of expecting the following to give me an aggregation which  
> groups the results only by hour:
> 
> curl [http://localhost:9000/stream/\_search](http://localhost:9000/stream/_search) -d '{  
> "aggs" : {  
> "visitor\_count" : { "date\_histogram" : { "field" : "created\_at", "interval" : "hour"} }  
> }  
> }'
> 
> As it stands, it does group by hour, but it's also grouped by day. (I end  
> up with 24 results for each day I have data).
> 
> I understand this is correct however, I would like to understand how it  
> possible to group this only by the hour so I have 24 results only?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/acaa2d16-8ef1-4dd9-a9e1-7c48cd9feb53%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/acaa2d16-8ef1-4dd9-a9e1-7c48cd9feb53%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Antonio\_Augusto\_Sant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antonio_augusto_sant/32/82851_2.png) [@Antonio\_Augusto\_Sant](https://discuss.elastic.co/u/Antonio_Augusto_Sant)\
**Post date:** [July 9, 2014, 1:13am UTC](https://discuss.elastic.co/t/aggregating-by-hour/18522/3 "2014-07-09T01:13:57Z")

</div>

You can use The histogram aggregate and use a script with something like document[@timestamp].hour

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/93c6d39c-f5b4-449e-bf6e-f28fa05407e1%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/93c6d39c-f5b4-449e-bf6e-f28fa05407e1%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Jenny\_Blunt](https://avatars.discourse-cdn.com/v4/letter/j/96bed5/32.png) [@Jenny\_Blunt](https://discuss.elastic.co/u/Jenny_Blunt)\
**Post date:** [July 9, 2014, 10:46am UTC](https://discuss.elastic.co/t/aggregating-by-hour/18522/4 "2014-07-09T10:46:57Z")

</div>

Sort of trying to stay away from scripting after we ran out of juice  
recently. Seems to take a reasonably large amount of memory for each run?

We're using the for about 100million records.

In the end, I added an hour and day field to Mongo when processing the raw  
data. That way we can use a really simple terms aggregation with a filter.

Will have a look at the 'document[@timestamp].hour' idea though and see  
what it's like

Cheers!

On Wednesday, 9 July 2014 02:13:57 UTC+1, Antonio Augusto Santos wrote:

> You can use The histogram aggregate and use a script with something like  
> document[@timestamp].hour

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/393c5449-9193-4f2b-a633-c73c1636d683%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/393c5449-9193-4f2b-a633-c73c1636d683%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:17am UTC](https://discuss.elastic.co/t/aggregating-by-hour/18522/5 "2017-07-06T01:17:01Z")

</div>


