# Calculating the Sum of a field by grouping

**URL:** <https://discuss.elastic.co/t/calculating-the-sum-of-a-field-by-grouping/363411>\
**Category:** Logstash\
**Created:** [July 19, 2024, 10:06am UTC](https://discuss.elastic.co/t/calculating-the-sum-of-a-field-by-grouping/363411 "2024-07-19T10:06:15Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![venkatkumar229](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/venkatkumar229/32/104663_2.png) [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Post date:** [July 19, 2024, 10:06am UTC](https://discuss.elastic.co/t/calculating-the-sum-of-a-field-by-grouping/363411/1 "2024-07-19T10:06:15Z")

</div>

Hi Team,

I am trying to merge two documents based on a common key in logstash and i am able to achieve this by using a elastic input filter and elastic filter in filter section for the lookup data. Now i wanted to calculate the sum of the price for each shop and add it into the index3 as a field. Could you please help how i can achieve this in the same logstash pipeline.

The data before merging:  
index1:

```auto
Source price shop_id	
AMAZON 234 12345	
AMAZON 44 12345	
AMAZON 6 12345

```

My index2:  
shop amount

* * *

12345 400

Combined index3 based on shop:

```auto
Source1 price	total_price	shop_id1	shop_id2	amount
AMAZON 234	284 12345	12345	400
AMAZON 44 284 12345 12345	400
AMAZON 6 284 12345	12345	400

```

My current logstash pipeline config  
input {  
elasticsearch {  
cloud\_id =\> "xxxxxxxxxxxxxxxxxxxx"  
proxy =\> "xxxxxxxxxxxxxxx"  
index =\> "index1"  
query =\> '{"query": {"match\_phrase": {"information": "MOV\_VN\_8599771"}}}'  
ssl =\> true  
user =\> "xxxxxxxxxx"  
password =\> "xxxxxxxxxxxxx"  
}  
}

filter {  
elasticsearch {  
cloud\_id =\> "xxxxxxxxxxxxxxx"  
proxy =\> "xxxxxxxxxxxxxxxx"  
index =\> "index2"  
query =\> "information:%{[information]}"  
ssl =\> true  
user =\> "xxxxxxxxxxxxx"  
password =\> "xxxxxxxxxxxxxxxxxx"  
fields =\> {  
"[source]" =\> "[source]"  
"[price]" =\> "[price]"  
"[shop]" =\> "[shop]"  
}  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
cloud\_id =\> "xxxxxxxxxxxx"  
proxy =\> "xxxxxxxxxxxx"  
index =\> "index3"  
ssl =\> true  
user =\> "xxxxxxxxxxxx"  
password =\> "xxxxxxxxxxx"  
action =\> "create"  
}  
}

is there any way i can achieve the grouping in the same logstash pipeline to get my desired utput.
