# Aggregation query in logstash input

**URL:** <https://discuss.elastic.co/t/aggregation-query-in-logstash-input/307006>\
**Category:** Logstash\
**Created:** [June 13, 2022, 8:59am UTC](https://discuss.elastic.co/t/aggregation-query-in-logstash-input/307006 "2022-06-13T08:59:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![S-elk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s-elk/32/98464_2.png) [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Post date:** [June 13, 2022, 8:59am UTC](https://discuss.elastic.co/t/aggregation-query-in-logstash-input/307006/1 "2022-06-13T08:59:46Z")

</div>

Hi! I am trying to get the results of an aggregations query with logstash.

Via dev tools this query works correctly but when passing it to logstash it ingests metadata but nothing related to max, min etc fields I am expecting.

this is my query:

```auto
{
  "size" : 0,
  "query" : {
    "bool" : {
      "must" : [
        {
          "term" : {
            "Metric-Type.keyword" : {
              "value" : "service-response-time",
              "boost" : 1.0
            }
          }
        },
        {
          "range" : {
          "@timestamp" : {
            "gt" : "now-7d/d",
            "lte" : "now"
          }
          }
        }
      ],
      "adjust_pure_negative" : true,
      "boost" : 1.0
    }
  },
  "_source" : false,
  "aggregations" : {
    "groupby" : {
      "filters" : {
        "filters" : [
          {
            "match_all" : {
              "boost" : 1.0
            }
          }
        ],
        "other_bucket" : false,
        "other_bucket_key" : "_other_"
      },
      "aggregations" : {
        "stats" : {
          "stats" : {
            "field" : "ValueMetric"
          }
        }
      }
    }
  }
}

```

and the result:

```auto
{
  "took" : 2114,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 10000,
      "relation" : "gte"
    },
    "max_score" : null,
    "hits" : []
  },
  "aggregations" : {
    "groupby" : {
      "buckets" : [
        {
          "doc_count" : 4297112,
          "stats" : {
            "count" : 4297112,
            "min" : 0.0,
            "max" : 3042730.0,
            "avg" : 336.3420319873068,
            "sum" : 1.44529938175704E9
          }
        }
      ]
    }
  }
}

```

and the result indexed by logstash:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/9/09e150d44e65ba9714d01af20d34f1228e52c522.png)

Thanks in advanced!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2022, 8:59am UTC](https://discuss.elastic.co/t/aggregation-query-in-logstash-input/307006/2 "2022-07-11T08:59:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
