# Calculation over aggregation results

**URL:** <https://discuss.elastic.co/t/calculation-over-aggregation-results/25929>\
**Category:** Elasticsearch\
**Created:** [July 20, 2015, 4:57pm UTC](https://discuss.elastic.co/t/calculation-over-aggregation-results/25929 "2015-07-20T16:57:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrei\_Grigorev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrei_grigorev/32/3791_2.png) [@Andrei\_Grigorev](https://discuss.elastic.co/u/Andrei_Grigorev)\
**Post date:** [July 20, 2015, 4:57pm UTC](https://discuss.elastic.co/t/calculation-over-aggregation-results/25929/1 "2015-07-20T16:57:46Z")

</div>

I am using ES 1.6.0.

Suppose we have following documents indexed under type "t" in index "test":

```
[
    { 
        // ...
        "_source": {
                        "id": "t2",
                        "ts": "2015-07-20T08:30"
                    }
    },
    {
        "_source": {
                        "id": "t1",
                        "ts": "2015-07-20T08:00"
                    }
    },
    {
        "_source": {
                        "id": "t1",
                        "ts": "2015-07-20T09:00"
                    }
    },
    {
        "_source": {
                        "id": "t2",
                        "ts": "2015-07-20T09:30"
                    }
    }
]

```

I want to bucketize it by "id" and for each distinct id figure out the difference between min and max value of "ts" field. Aggregation itself is easy:

```
{
    "aggs": {
                 "id": {
                            "terms": {
                                          "field": "id"
                                      },
                            "aggs": {
                                         "mit": {
                                                     "min": {
                                                                 "field": "ts"
                                                             }
                                                 },
                                         "mat": {
                                                     "max": {
                                                                 "field": "ts"
                                                             }
                                                 }
                                     }
                        }
             }
}

```

But now I need to do actual subtraction and I did not find a way so far. Is it possible? How?

OK, I might not provide the details why I need it. I want to graph it in Kibana, so if can be done in Kibana instead, it is fine, too.

---

<div class="post-metadata">

**Author:** ![msimos](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@msimos](https://discuss.elastic.co/u/msimos)\
**Post date:** [July 21, 2015, 12:43am UTC](https://discuss.elastic.co/t/calculation-over-aggregation-results/25929/2 "2015-07-21T00:43:32Z")

</div>

You might try a metric aggregation:

1. [link to stackoverflow](http://stackoverflow.com/questions/23514456/how-to-subtract-aggregate-min-from-aggreagate-maxdifference-in-es)

2. [https://www.elastic.co/guide/en/elasticsearch/reference/1.5/search-aggregations-metrics-scripted-metric-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/1.5/search-aggregations-metrics-scripted-metric-aggregation.html)

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [July 21, 2015, 8:24am UTC](https://discuss.elastic.co/t/calculation-over-aggregation-results/25929/3 "2015-07-21T08:24:31Z")

</div>

In 2.0 there is a new feature called [pipeline aggregations](https://www.elastic.co/guide/en/elasticsearch/reference/master/search-aggregations-pipeline.html) which allows you to do post-processing of aggregations results like this. The aggregation you would use for this would be the [`bucket_script` aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/master/search-aggregations-pipeline-bucket-script-aggregation.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:00am UTC](https://discuss.elastic.co/t/calculation-over-aggregation-results/25929/4 "2017-07-06T00:00:14Z")

</div>


