# Can unix timestamp be used as field in date histogram?

**URL:** <https://discuss.elastic.co/t/can-unix-timestamp-be-used-as-field-in-date-histogram/8357>\
**Category:** Elasticsearch\
**Created:** [July 9, 2012, 9:45am UTC](https://discuss.elastic.co/t/can-unix-timestamp-be-used-as-field-in-date-histogram/8357 "2012-07-09T09:45:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![komaln](https://avatars.discourse-cdn.com/v4/letter/k/8797f3/32.png) [@komaln](https://discuss.elastic.co/u/komaln)\
**Post date:** [July 9, 2012, 9:45am UTC](https://discuss.elastic.co/t/can-unix-timestamp-be-used-as-field-in-date-histogram/8357/1 "2012-07-09T09:45:50Z")

</div>

Hi,

I am building a log analysis tool and want to create the timeline series  
graph of the number of log entries logged.

I wish to use the date histogram feature for it. A query like:  
"facets" : {  
"histo1" : {  
"date\_histogram" : {  
"field" : "field\_name",  
"interval" : "day"  
}  
}  
}  
would work just fine for me. I dont have any field in the "date" format, so  
I was wondering if I can use the unix timestamp field I have indexed in my  
elasticsearch for the same purpose. Its a date in different format.

I tried a couple of things myself, didnt work. Can you please suggest?

Thanks and Regards,  
Komal.

---

<div class="post-metadata">

**Author:** ![fonzo14](https://avatars.discourse-cdn.com/v4/letter/f/898d66/32.png) [@fonzo14](https://discuss.elastic.co/u/fonzo14)\
**Post date:** [July 10, 2012, 6:54am UTC](https://discuss.elastic.co/t/can-unix-timestamp-be-used-as-field-in-date-histogram/8357/2 "2012-07-10T06:54:46Z")

</div>

I guess you could try the "script" histogram facet :

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

"facets" : {  
"histo1" : {  
"histogram" : {  
"key\_script" : "doc['date'].date.minuteOfHour",  
"value\_script" : "doc['num1'].value",  
}  
}  
}

> I tried a couple of things myself, didnt work. Can you please suggest?

---

<div class="post-metadata">

**Author:** ![komaln](https://avatars.discourse-cdn.com/v4/letter/k/8797f3/32.png) [@komaln](https://discuss.elastic.co/u/komaln)\
**Post date:** [July 10, 2012, 9:18am UTC](https://discuss.elastic.co/t/can-unix-timestamp-be-used-as-field-in-date-histogram/8357/3 "2012-07-10T09:18:07Z")

</div>

Hey,

I thought about using this but I dont have the "value" component. I want  
the date histogram of the number of entries indexed using elasticsearch and  
there is no "value" indicating it. Kindly correct me if I am wrong.

Thanks and Regards,  
Komal.

On Tuesday, July 10, 2012 12:24:46 PM UTC+5:30, fonzo14 wrote:

> I guess you could try the "script" histogram facet :  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/api/search/facets/histogram-facet.html)
> 
> "facets" : {  
> "histo1" : {  
> "histogram" : {  
> "key\_script" : "doc['date'].date.minuteOfHour",  
> "value\_script" : "doc['num1'].value",  
> }  
> }  
> }
> 
> > I tried a couple of things myself, didnt work. Can you please suggest?

---

<div class="post-metadata">

**Author:** ![Colin\_Dellow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colin_dellow/32/2818_2.png) [@Colin\_Dellow](https://discuss.elastic.co/u/Colin_Dellow)\
**Post date:** [July 10, 2012, 3:07pm UTC](https://discuss.elastic.co/t/can-unix-timestamp-be-used-as-field-in-date-histogram/8357/4 "2012-07-10T15:07:23Z")

</div>

On Monday, 9 July 2012 05:45:50 UTC-4, Komal wrote:

> Hi,
> 
> I am building a log analysis tool and want to create the timeline series  
> graph of the number of log entries logged.
> 
> I wish to use the date histogram feature for it. A query like:  
> "facets" : {  
> "histo1" : {  
> "date\_histogram" : {  
> "field" : "field\_name",  
> "interval" : "day"  
> }  
> }  
> }  
> would work just fine for me. I dont have any field in the "date" format,  
> so I was wondering if I can use the unix timestamp field I have indexed in  
> my elasticsearch for the same purpose. Its a date in different format.
> 
> I tried a couple of things myself, didnt work. Can you please suggest?

What exactly did you try? If you are indexing a timestamp with seconds  
resolution rather than milliseconds resolution, look at the factor  
parameter for date histogram. (See

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

).

---

<div class="post-metadata">

**Author:** ![komaln](https://avatars.discourse-cdn.com/v4/letter/k/8797f3/32.png) [@komaln](https://discuss.elastic.co/u/komaln)\
**Post date:** [July 11, 2012, 5:11am UTC](https://discuss.elastic.co/t/can-unix-timestamp-be-used-as-field-in-date-histogram/8357/5 "2012-07-11T05:11:15Z")

</div>

Hey Colin,

Yes, I missed the "factor" part. Many thanks. Its working fine now :).

Thanks,  
Komal.

On Tuesday, July 10, 2012 8:37:23 PM UTC+5:30, Colin Dellow wrote:

> On Monday, 9 July 2012 05:45:50 UTC-4, Komal wrote:
> 
> > Hi,
> > 
> > I am building a log analysis tool and want to create the timeline series  
> > graph of the number of log entries logged.
> > 
> > I wish to use the date histogram feature for it. A query like:  
> > "facets" : {  
> > "histo1" : {  
> > "date\_histogram" : {  
> > "field" : "field\_name",  
> > "interval" : "day"  
> > }  
> > }  
> > }  
> > would work just fine for me. I dont have any field in the "date" format,  
> > so I was wondering if I can use the unix timestamp field I have indexed in  
> > my elasticsearch for the same purpose. Its a date in different format.
> > 
> > I tried a couple of things myself, didnt work. Can you please suggest?
> 
> What exactly did you try? If you are indexing a timestamp with seconds  
> resolution rather than milliseconds resolution, look at the factor  
> parameter for date histogram. (See  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/api/search/facets/date-histogram-facet.html)  
> ).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:20am UTC](https://discuss.elastic.co/t/can-unix-timestamp-be-used-as-field-in-date-histogram/8357/6 "2017-07-06T03:20:38Z")

</div>


