# Aggregation filter Logstash

**URL:** <https://discuss.elastic.co/t/aggregation-filter-logstash/279868>\
**Category:** Logstash\
**Created:** [July 28, 2021, 1:44pm UTC](https://discuss.elastic.co/t/aggregation-filter-logstash/279868 "2021-07-28T13:44:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roberto\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_b/32/77615_2.png) [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Post date:** [July 28, 2021, 1:44pm UTC](https://discuss.elastic.co/t/aggregation-filter-logstash/279868/1 "2021-07-28T13:44:37Z")

</div>

Hi all,

i'm trying to use aggregation filter, i have a big result set (more than 140k rows from mySql).  
And the aggregation stopped **always** at row 53.  
In the log I can see this error:

```auto
[ERROR][logstash.javapipeline][main] Pipeline error {:pipeline_id=>"main", :exception=>#<LogStash::ConfigurationError: Aggregate plugin: For task_id pattern '%{id}', there are more than one filter which defines timeout options. All timeout options have to be defined in only one aggregate filter per task_id pattern. Timeout options are : timeout, inactivity_timeout, timeout_code, push_map_as_event_on_timeout, push_previous_map_as_event, timeout_timestamp_field, timeout_task_id_field, timeout_

```

the aggregation filter is the following (I ommitted many rows):

```auto
filter {
aggregate {
task_id => "%{id}"
code => "
map['id'] = event.get('id')
map['tas'] = event.get('tas')
...
...
...
map['dati_sospensione'] ||= []
map['dati_sospensione'] << { 'stato_sospensione_id' => event.get('stato_sospensione_id'), 'data_fine_sospensione' => event.get('data_fine_sospensione'),
'data_fine_sospensione' => event.get('data_fine_sospensione'), 'sospensione_stato_attiva' => event.get('sospensione_stato_attiva'),
'stato_sospensione_user_ins' => event.get('stato_sospensione_user_ins'), 'stato_sospensione_data_ins' => event.get('stato_sospensione_data_ins'),
'stato_sospensioni_user_mod' => event.get('stato_sospensioni_user_mod'), 'stato_sospensioni_data_mod' => event.get('stato_sospensioni_data_mod')}
event.cancel()
"
timeout_task_id_field => "id"
timeout => 10
push_previous_map_as_event => true
}
}

```

Maybe the problem is on the mapping?!

A hug and a kiss to anyone can help me, i'm going crazy.

KR

Roberto

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2021, 1:45pm UTC](https://discuss.elastic.co/t/aggregation-filter-logstash/279868/2 "2021-08-25T13:45:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
