# Aggregation by sum of field

**URL:** <https://discuss.elastic.co/t/aggregation-by-sum-of-field/43621>\
**Category:** Logstash\
**Created:** [March 7, 2016, 5:58am UTC](https://discuss.elastic.co/t/aggregation-by-sum-of-field/43621 "2016-03-07T05:58:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)\
**Post date:** [March 7, 2016, 5:58am UTC](https://discuss.elastic.co/t/aggregation-by-sum-of-field/43621/1 "2016-03-07T05:58:20Z")

</div>

Hi ,

If I want to aggregate by sum of specific field (for example build).  
Can you give me an example to upload all the fields from the json file and also the ability to aggregate by sum of build ?  
This is my conf file:  
input {  
file{  
path =\> ["/tmp/TEST.json"]  
type =\> "json"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}  
filter{  
grok {  
match =\> ['message', '(?"TestName":.\*"Agent":"[^"]+")' ]  
}  
mutate {  
convert =\> { "build" =\> "float" }  
}  
json {  
source =\> "message"  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
host =\> "[XX.xx.xx.xxx](http://XX.xx.xx.xxx)"  
protocol =\> "http"  
index =\> "index\_j"  
}  
}

BR,  
Chen

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2016, 6:36pm UTC](https://discuss.elastic.co/t/aggregation-by-sum-of-field/43621/2 "2016-03-07T18:36:24Z")

</div>

> Can you give me an example to upload all the fields from the json file

Logstash will send all fields in the event to ES. You should be fine with the json filter that you have.

What looks suspicious is the mutate filter that attempts to change the type of the `build` field. Where does that field come from? Keep in mind that filters are applied in order. Perhaps the mutate filter should go after the json filter?

> and also the ability to aggregate by sum of build ?

In Kibana?

---

<div class="post-metadata">

**Author:** ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)\
**Post date:** [March 8, 2016, 7:36am UTC](https://discuss.elastic.co/t/aggregation-by-sum-of-field/43621/3 "2016-03-08T07:36:00Z")

</div>

Hi ,

I changes my Json file , first all the fields where like this: "key":"value"  
For key's that are not string , I changed it to "Key":value (without the " character).  
Also removed the mutate after I changed my Json file.  
Now it's ok , and I can also aggregate by those fields in Kibana.

Thanks 🙂

BR,  
Chen

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:08am UTC](https://discuss.elastic.co/t/aggregation-by-sum-of-field/43621/4 "2017-07-06T05:08:02Z")

</div>


