# Aggregation from Elasticsearch filter in Logstash

**URL:** <https://discuss.elastic.co/t/aggregation-from-elasticsearch-filter-in-logstash/126802>\
**Category:** Logstash\
**Created:** [April 4, 2018, 6:33pm UTC](https://discuss.elastic.co/t/aggregation-from-elasticsearch-filter-in-logstash/126802 "2018-04-04T18:33:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![roblopes](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@roblopes](https://discuss.elastic.co/u/roblopes)\
**Post date:** [April 4, 2018, 6:33pm UTC](https://discuss.elastic.co/t/aggregation-from-elasticsearch-filter-in-logstash/126802/1 "2018-04-04T18:33:18Z")

</div>

I have a very tiny index (around 10 documents), having some important information, being one of them an attribute called number\_of\_days.

What I am trying to do is run a simple query to retrieve document with the bigger number in that attribute. Something like this:

elasticsearch {  
hosts =\> ["server1:9200"]  
index =\> "expiration"  
query =\> '{"query": {"match\_all": {}},"size": 0,"aggs" : {"max\_expiration" : { "max" : { "field" : "days\_to\_expire" } }}}'  
fields =\> { "max\_expiration" =\> "[@metadata][max\_expiration]" }  
}

However it is not working, and reading though other topics, it seems that logstash doesn't work with aggregations. So, how can I fix this problem? I mean, get the biggest number from an index, and assign that value to a variable?

Thanks,  
Rob

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 4, 2018, 6:45pm UTC](https://discuss.elastic.co/t/aggregation-from-elasticsearch-filter-in-logstash/126802/2 "2018-04-04T18:45:22Z")

</div>

Without aggregations, the easiest way to get the largest value for a field is via a [sorted search](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-sort.html) that retrieves at-most-one document:

```auto
{"query": {"match_all": {}}, "size":1, "sort": [{"days_to_expire": "desc"}]}

```

---

<div class="post-metadata">

**Author:** ![roblopes](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@roblopes](https://discuss.elastic.co/u/roblopes)\
**Post date:** [April 4, 2018, 6:47pm UTC](https://discuss.elastic.co/t/aggregation-from-elasticsearch-filter-in-logstash/126802/3 "2018-04-04T18:47:19Z")

</div>

kkk... It's so simple that I'm embarrassed. Yes, smart way to fix the problem. Who cares aggregations! 🙂

That makes the trick.

Thanks a lot!  
Rob

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2018, 6:47pm UTC](https://discuss.elastic.co/t/aggregation-from-elasticsearch-filter-in-logstash/126802/4 "2018-05-02T18:47:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
