# Aggregation error - nil can't be coerced into Fixnum

**URL:** <https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678>\
**Category:** Logstash\
**Created:** [February 16, 2019, 10:09am UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678 "2019-02-16T10:09:43Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 16, 2019, 10:09am UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/1 "2019-02-16T10:09:43Z")

</div>

Hi,

I am trying to understand what is wrong with my aggregation:

**My code:**

```
 aggregate {
          task_id => "%{ResolutionDate}"
          code => "
                   map['Date'] = event.get('ResolutionDate')
                   map['TotalNonPrimeTimeUnavailabilityinSeconds'] ||= 0 
                   map['TotalNonPrimeTimeUnavailabilityinSeconds'] += event.get('NonPrimeTimeUnavailabilityinSeconds')
                   map['TotalBusinessTimeUnavailabilityinSeconds'] ||= 0 
                   map['TotalBusinessTimeUnavailabilityinSeconds'] += event.get('BusinessTimeUnavailabilityinSeconds')
                   if event.get('Classification').eql?('High')
                                map['CountClassificationHigh'] ||= 0; map['CountClassificationHigh'] += 1; 
                   elsif event.get('Classification').eql?('Low')
                                map['CountClassificationLow'] ||= 0; map['CountClassificationLow'] += 1;
                   end
                   #event.cancel()
          "
          push_previous_map_as_event => true
          map_action => "create_or_update"
          push_map_as_event_on_timeout => true
          timeout => 300
          inactivity_timeout => 30
 }

```

**The error:**

`[2019-02-16T12:04:28,410][ERROR][logstash.filters.aggregate] Aggregate exception occurred {:error=>#<TypeError: nil can't be coerced into Fixnum>, :code=>"\n map['Date'] = event.get('ResolutionDate')\n map['TotalNonPrimeTimeUnavailabilityinSeconds'] ||= 0 \n map['TotalNonPrimeTimeUnavailabilityinSeconds'] += event.get('NonPrimeTimeUnavailabilityinSeconds')\n map['TotalBusinessTimeUnavailabilityinSeconds'] ||= 0 \n map['TotalBusinessTimeUnavailabilityinSeconds'] += event.get('BusinessTimeUnavailabilityinSeconds')\n if event.get('Classification').eql?('High')\n map['CountClassificationHigh'] ||= 0; map['CountClassificationHigh'] += 1; \n elsif event.get('Classification').eql?('Low')\n map['CountClassificationLow'] ||= 0; map['CountClassificationLow'] += 1;\n end\n #event.cancel()\n ", :map=>{"Date"=>2018-09-10T05:22:16.000Z, "TotalNonPrimeTimeUnavailabilityinSeconds"=>0}, :event_data=>{"Status"=>"Fechado", "Organization Support Group"=>"Sustenta\\xE7\\xE3o", "Create Date"=>"2018-09-09 16:20:24", "INCIDENTE"=>"INC000004054472", "Company"=>"AMDOCS do Brasil", "Resolution Date"=>"2018-09-10 08:22:16", "BusinessTimeContractCommitment"=>"99.5", "@metadata"=>{"host"=>"SHARONSA03", "path"=>"C:/Users/sharonsa/Work/GSS/VIVO/kpi/BaseIncidentes.csv"}, "type"=>"csv", "message"=>"INC000004054472,Fechado,AMDOCS do Brasil,Sustenta\\xE7\\xE3o,Suporte Funcional N2 - OMS - Ordens,2018-09-09 16:20:24,2018-09-10 08:22:16,,,\\r", "CreateDate"=>2018-09-09T13:20:24.000Z, "Designated Group"=>"Suporte Funcional N2 - OMS - Ordens", "path"=>"C:/Users/sharonsa/Work/GSS/VIVO/kpi/BaseIncidentes.csv", "@timestamp"=>2019-02-16T10:04:25.361Z, "NonPrimeTimeContractCommitment"=>"98", "Classification"=>"\\r", "@version"=>"1", "host"=>"SHARONSA03", "ResolutionDate"=>2018-09-10T05:22:16.000Z}}`

Thanks  
Sharon

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 16, 2019, 12:42pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/2 "2019-02-16T12:42:11Z")

</div>

> [@ssasporta](#):
>
> map['TotalBusinessTimeUnavailabilityinSeconds'] += event.get('BusinessTimeUnavailabilityinSeconds')

There is no BusinessTimeUnavailabilityinSeconds field in the event\_data shown, so event.get returns nil, but it needs a fixnum to add it to zero. It will not coerce that.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 16, 2019, 12:56pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/3 "2019-02-16T12:56:19Z")

</div>

**My aggregation code now looks like that:**

```
     aggregate {
              task_id => "%{ResolutionDate}"
              code => "
                       map['Date'] = event.get('ResolutionDate')
                       if event.get('NonPrimeTimeUnavailabilityinSeconds').to_i > 0
                              map['TotalNonPrimeTimeUnavailabilityinSeconds'] ||= 0; map['TotalNonPrimeTimeUnavailabilityinSeconds'] += event.get('NonPrimeTimeUnavailabilityinSeconds').to_i;
                       end
                       if event.get('BusinessTimeUnavailabilityinSeconds').to_i > 0
                              map['TotalBusinessTimeUnavailabilityinSeconds'] ||= 0; map['TotalBusinessTimeUnavailabilityinSeconds'] += event.get('BusinessTimeUnavailabilityinSeconds').to_i;
                       end
                       if event.get('Classification').eql?('High')
                                    map['CountClassificationHigh'] ||= 0; map['CountClassificationHigh'] += 1; 
                       elsif event.get('Classification').eql?('Low')
                                    map['CountClassificationLow'] ||= 0; map['CountClassificationLow'] += 1;
                       end
                       #event.cancel()
              "
              push_previous_map_as_event => true
              map_action => "create_or_update"
              push_map_as_event_on_timeout => true
              timeout => 300
              inactivity_timeout => 30
     }

```

**No more errors in the log** , but I don't see the aggregated fields in the Kibana.

Should they appears on the event like all the other fields?

Thanks  
Sharon.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 16, 2019, 1:04pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/4 "2019-02-16T13:04:55Z")

</div>

> [@ssasporta](#):
>
> Should they appears on the event like all the other fields?

Yes.

Note that in the event\_data in your first post, you have "Classification"=\>"\r", so that would not trigger either branch of the if/elsif.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 16, 2019, 5:46pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/5 "2019-02-16T17:46:33Z")

</div>

Can't see any of the aggregation fields in the Kibana.

No errors / info/warnings in the log.

Any idea?

Thanks  
Sharon.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 16, 2019, 6:36pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/6 "2019-02-16T18:36:39Z")

</div>

Make one of the added fields unconditional

```
map['JustTesting'] ||= 0; map['JustTesting'] += 1; 

```

If that shows up then the problem is that your events do not trigger any of the conditionals.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 16, 2019, 8:21pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/7 "2019-02-16T20:21:02Z")

</div>

> [@Badger](#):
>
> map['JustTesting'] ||= 0; map['JustTesting'] += 1;

It doesn't show up.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 16, 2019, 8:42pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/8 "2019-02-16T20:42:06Z")

</div>

> [@ssasporta](#):
>
> Should they appears on the event like all the other fields?

When I said yes, I should have said no. Consider this file

```auto
{ "ResolutionDate": 3 }
{ "ResolutionDate": "foo" }

```

and this configuration

```
    json { source => "message" }
    aggregate {
        task_id => "%{ResolutionDate}"
        code => "map['JustTesting'] ||= 0; map['JustTesting'] += 1"
        timeout_task_id_field => "Date"
        push_previous_map_as_event => true
        map_action => "create_or_update"
        push_map_as_event_on_timeout => true
        timeout => 8
        inactivity_timeout => 4
    }

```

That will get you

```auto
{
           "message" => "{ \"ResolutionDate\": 3 }",
        "@timestamp" => 2019-02-16T20:39:49.724Z,
          "@version" => "1",
    "ResolutionDate" => 3,
              "path" => "/home/user/foo.json"
}
{
           "message" => "{ \"ResolutionDate\": \"foo\" }",
        "@timestamp" => 2019-02-16T20:39:49.726Z,
          "@version" => "1",
    "ResolutionDate" => "foo",
              "path" => "/home/user/foo.json"
}
{
    "JustTesting" => 1,
     "@timestamp" => 2019-02-16T20:39:49.837Z,
       "@version" => "1",
           "Date" => "3"
}
{
    "JustTesting" => 1,
     "@timestamp" => 2019-02-16T20:39:54.804Z,
       "@version" => "1",
           "Date" => "foo"
}

```

Note that you get the third event immediately after the second (that's being triggered by 'push\_previous\_map\_as\_event =\> true') and then the final event comes 5 seconds later (driven by 'push\_map\_as\_event\_on\_timeout =\> true').

If the field ResolutionDate does not exist then nothing gets aggregated.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 17, 2019, 12:42pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/9 "2019-02-17T12:42:54Z")

</div>

What ever I am trying to do, I am nor getting the aggregations.

I used in the task\_id the field named: INCIDENTE, which for sure exist in any event, but still can't see the aggregated fields.

My aggregation looks like that:

```
 aggregate {
            task_id => "%{INCIDENTE}"
            code => "
                     if event.get('NonPrimeTimeUnavailabilityinSeconds').to_i > 0
                            map['TotalNonPrimeTimeUnavailabilityinSeconds'] ||= 0; map['TotalNonPrimeTimeUnavailabilityinSeconds'] += event.get('NonPrimeTimeUnavailabilityinSeconds').to_i;
                     end
                     if event.get('BusinessTimeUnavailabilityinSeconds').to_i > 0
                            map['TotalBusinessTimeUnavailabilityinSeconds'] ||= 0; map['TotalBusinessTimeUnavailabilityinSeconds'] += event.get('BusinessTimeUnavailabilityinSeconds').to_i;
                     end
                     if event.get('Classification').eql?('High')
                                  map['CountClassificationHigh'] ||= 0; map['CountClassificationHigh'] += 1; 
                     elsif event.get('Classification').eql?('Low')
                                  map['CountClassificationLow'] ||= 0; map['CountClassificationLow'] += 1;
                     end                           
            "
            timeout_task_id_field => "Incident"
            push_previous_map_as_event => true
            map_action => "create_or_update"
            push_map_as_event_on_timeout => true
            timeout => 200
            inactivity_timeout => 5
 }

```

I changed the log to debug mode but I can't see something wrong there.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 20, 2019, 8:58pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/10 "2019-02-20T20:58:14Z")

</div>

Simple aggregation like that, still doesn't work for me:

```
         aggregate {
                    task_id => "%{INCIDENTE}"
                    code => "
                             map['JustTesting'] ||= 0; map['JustTesting'] += 1
                    "
         }

```

What do I need to continue and check to understand what it wrong?

Regards,  
Sharon.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 20, 2019, 10:15pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/11 "2019-02-20T22:15:29Z")

</div>

Nothing will trigger the aggregation being pushed as an event in that case. I think the minimum that will work is below. I created a file that contains

```
{ "INCIDENTE" : 0 }

```

Then I run with this configuration

```
input { file { path => "/home/user/foo.json" sincedb_path => "/dev/null" start_position => "beginning" } }
filter {
    json { source => "message" }
    aggregate {
                task_id => "%{INCIDENTE}"
                code => "
                     map['JustTesting'] ||= 0; map['JustTesting'] += 1
                "
                push_map_as_event_on_timeout => true
                inactivity_timeout => 2

     }
}
output { stdout { codec => rubydebug } }

```

Using a file input is important, because if you a generator the pipeline will stop executing, and there will be no thread running that can execute the timeout code. That config gets me

```auto
[2019-02-20T17:09:24,994][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
{
    "@timestamp" => 2019-02-20T22:09:24.992Z,
     "INCIDENTE" => 0,
          "path" => "/home/user/foo.json",
       "message" => "{ \"INCIDENTE\" : 0 }",
      "@version" => "1"
}
{
     "@timestamp" => 2019-02-20T22:09:30.075Z,
    "JustTesting" => 1,
       "@version" => "1"
}

```

If on the other hand I use a generator input

```
input { generator { count => 1 message => '{ "INCIDENTE" : 0 }' } }

```

Then with that same filter I get

```auto
[2019-02-20T17:14:15,587][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
{
    "@timestamp" => 2019-02-20T22:14:15.565Z,
      "sequence" => 0,
     "INCIDENTE" => 0,
       "message" => "{ \"INCIDENTE\" : 0 }",
      "@version" => "1"
}
[2019-02-20T17:14:15,734][INFO][logstash.pipeline] Pipeline has terminated {:pipeline_id=>"main", :thread=>"#<Thread:0x3765a362 run>"}

```

with no aggregation.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 20, 2019, 10:32pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/12 "2019-02-20T22:32:43Z")

</div>

I am getting as input a csv file.

**The events looks like that:**

`INC000004074534,Fechado,Sonda IT,Gestão de Serviços de TI,Suporte Inicial N1,2018-09-14 20:07:39,2018-09-14 20:55:18,,,`

the first field is the **INCIDENTE**.

So, I assume your aggregation example, should work for me too.

I will put it in the Logstash and test. I will keep update.

Thanks  
Sharon.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 20, 2019, 10:35pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/13 "2019-02-20T22:35:52Z")

</div>

Maybe the problem is that I don't have a source field ?

I can't see a **source field** in output in Kibana.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 20, 2019, 10:39pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/14 "2019-02-20T22:39:22Z")

</div>

> [@ssasporta](#):
>
> INC000004074534,Fechado,Sonda IT,Gestão de Serviços de TI,Suporte Inicial N1,2018-09-14 20:07:39,2018-09-14 20:55:18,,,

Can you show us that event in the JSON tab in Kibana?

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 20, 2019, 10:44pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/15 "2019-02-20T22:44:44Z")

</div>

> [@Badger](#):
>
> aggregate { task\_id =\> "%{INCIDENTE}" code =\> " map['JustTesting'] ||= 0; map['JustTesting'] += 1 " push\_map\_as\_event\_on\_timeout =\> true inactivity\_timeout =\> 2 }

```
{
  "_index": "logstash2019.02.20incidents-kpi",
  "_type": "doc",
  "_id": "IC65DGkBptv9o3KvOjpa",
  "_version": 1,
  "_score": null,
  "_source": {
    "BusinessTimeContractCommitment": 25.5,
    "Company": "Sooo IT",
    "CreateDate": "2019-01-20T18:09:58.000Z",
    "Resolution Date": "2019-01-21 07:59:55",
    "Organization Support Group": "Gestão de Serviços de TI",
    "@version": "1",
    "Designated Group": "Suporte Inicial N1",
    "NonPrimeTimeSecondsPerWeek": 226800,
    "ResolutionDate": "2019-01-21T05:59:55.000Z",
    "host": "TTT03",
    "@timestamp": "2019-02-20T21:04:19.358Z",
    "BusinessTimeSecondsPerWeek": 378000,
    "message": "INC000004567194,Resolvido,Sonda IT,Gestão de Serviços de TI,Suporte Inicial N1,2019-01-20 20:09:58,2019-01-21 07:59:55,,,\r",
    "path": "C:/Users/sharonsa/Work/kpi/BaseIncidentes.csv",
    "type": "csv",
    "INCIDENTE": "INC000004567194",
    "Create Date": "2019-01-20 20:09:58",
    "Status": "Resolvido",
    "NonPrimeTimeContractCommitment": 95
  },
  "fields": {
    "CreateDate": [
      "2019-01-20T18:09:58.000Z"
    ],
    "ResolutionDate": [
      "2019-01-21T05:59:55.000Z"
    ],
    "@timestamp": [
      "2019-02-20T21:04:19.358Z"
    ]
  },
  "sort": [
    1548050395000
  ]
}

```

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 20, 2019, 10:47pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/16 "2019-02-20T22:47:26Z")

</div>

Maybe it is not the same one, but other with the same format exactly.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 20, 2019, 11:10pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/17 "2019-02-20T23:10:42Z")

</div>

Do you have [dynamic mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic.html) disabled? Have you ever tried running logstash with this?

```
output { stdout { codec => rubydebug } }

```

I am wondering if logstash is adding the fields and elasticsearch is ignoring them. On your elasticsearch server try

```
curl -X GET "localhost:9200/logstash2019.02.20incidents-kpi/_mapping"

```

And look for "dynamic"

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 20, 2019, 11:16pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/18 "2019-02-20T23:16:51Z")

</div>

> [@Badger](#):
>
> dynamic

I can't find "dynamic" in it

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 20, 2019, 11:20pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/19 "2019-02-20T23:20:21Z")

</div>

OK, then I am out of ideas, at least for now.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 20, 2019, 11:26pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678/20 "2019-02-20T23:26:59Z")

</div>

Why can't I find the dynamic definition?

It need to be dynamic. I am not creating the mapping before loading my events.

[Next page](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678.md?page=2)
