# Calculate values over aggregation results

**URL:** <https://discuss.elastic.co/t/calculate-values-over-aggregation-results/184556>\
**Category:** Elasticsearch\
**Created:** [June 6, 2019, 10:27am UTC](https://discuss.elastic.co/t/calculate-values-over-aggregation-results/184556 "2019-06-06T10:27:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasony](https://avatars.discourse-cdn.com/v4/letter/j/a3d4f5/32.png) [@jasony](https://discuss.elastic.co/u/jasony)\
**Post date:** [June 6, 2019, 10:27am UTC](https://discuss.elastic.co/t/calculate-values-over-aggregation-results/184556/1 "2019-06-06T10:27:56Z")

</div>

Hello,

I am trying to ‘minus’ operation after below terms aggregation.

```
GET test02/_search
{
  "aggs": {
    "txid_aggs": {
      "terms": {
        "field": "txid.keyword",
        "size": 10
      },
      "aggs": {
        "logdate_aggs": {
          "terms": {
            "field": "logdate",
            "size": 10
          }
        }
      }
    }
  },
  "size": 0
}

```

result looks like below but i don’t know how i can do **minus** operation with "key " field values from the aggregation result  
(e.g. "2019-06-05T01:51:44.498Z" - "2019-06-05T01:51:48.498Z").

```
{
  "took" : 16,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : 6,
    "max_score" : 0.0,
    "hits" : []
  },
  "aggregations" : {
    "txid_aggs" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
       {
          "key" : "67890ba-d7db-4367-a0c8-fbeffb7c9dfb",
          "doc_count" : 2,
          "logdate_aggs" : {
            "doc_count_error_upper_bound" : 0,
            "sum_other_doc_count" : 0,
            "buckets" : [
              {
                "key" : 1559699504498,
                "key_as_string" : "2019-06-05T01:51:44.498Z",
                "doc_count" : 1
              },
              {
                "key" : 1559699508498,
                "key_as_string" : "2019-06-05T01:51:48.498Z",
                "doc_count" : 1
              }
            ]
          }
        }
      ]
    }
  }
}

```

please advise. thank you!!!

---

<div class="post-metadata">

**Author:** ![jasony](https://avatars.discourse-cdn.com/v4/letter/j/a3d4f5/32.png) [@jasony](https://discuss.elastic.co/u/jasony)\
**Post date:** [June 8, 2019, 1:39pm UTC](https://discuss.elastic.co/t/calculate-values-over-aggregation-results/184556/2 "2019-06-08T13:39:16Z")

</div>

Isn't it possible to perform calculation with "key" values after aggregation??

I just need the result from "1559699504498" - "1559699508498" from above aggregation result.

Please advise.

Thank you!

---

<div class="post-metadata">

**Author:** ![jasony](https://avatars.discourse-cdn.com/v4/letter/j/a3d4f5/32.png) [@jasony](https://discuss.elastic.co/u/jasony)\
**Post date:** [June 10, 2019, 11:48pm UTC](https://discuss.elastic.co/t/calculate-values-over-aggregation-results/184556/3 "2019-06-10T23:48:14Z")

</div>

Please advise

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [June 14, 2019, 1:12pm UTC](https://discuss.elastic.co/t/calculate-values-over-aggregation-results/184556/4 "2019-06-14T13:12:08Z")

</div>

I don't think there's a way to do exactly what you want, but maybe there's a creative workaround?

For example, are there always going to be two timestamps in each of the buckets for `txid.keyword`? In that case, you could calculate the `min` and the `max` values of `logdate`. Those you can then subtract using a `bucket_script` aggregation. The result would be something like this:

```auto
GET test02/_search
{
  "aggs": {
    "txid_aggs": {
      "terms": {
        "field": "txid.keyword",
        "size": 10
      },
      "aggs": {
        "min": {
          "min": {
            "field": "logdate"
          }
        },
        "max": {
          "max": {
            "field": "logdate"
          }
        },
        "diff": {
          "bucket_script": {
            "buckets_path": {
              "min": "min",
              "max": "max"
            },
            "script": "params.max - params.min"
          }
        }
      }
    }
  },
  "size": 0
}

```

---

<div class="post-metadata">

**Author:** ![jasony](https://avatars.discourse-cdn.com/v4/letter/j/a3d4f5/32.png) [@jasony](https://discuss.elastic.co/u/jasony)\
**Post date:** [June 14, 2019, 10:53pm UTC](https://discuss.elastic.co/t/calculate-values-over-aggregation-results/184556/5 "2019-06-14T22:53:47Z")

</div>

it works. thank you so much!!! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2019, 10:53pm UTC](https://discuss.elastic.co/t/calculate-values-over-aggregation-results/184556/6 "2019-07-12T22:53:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
