# Cannot get the aggregate plugin to work

**URL:** <https://discuss.elastic.co/t/cannot-get-the-aggregate-plugin-to-work/28570>\
**Category:** Logstash\
**Created:** [September 3, 2015, 12:32am UTC](https://discuss.elastic.co/t/cannot-get-the-aggregate-plugin-to-work/28570 "2015-09-03T00:32:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anoban](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anoban/32/3466_2.png) [@anoban](https://discuss.elastic.co/u/anoban)\
**Post date:** [September 3, 2015, 12:32am UTC](https://discuss.elastic.co/t/cannot-get-the-aggregate-plugin-to-work/28570/1 "2015-09-03T00:32:33Z")

</div>

I am trying to compute response times and therefore do a line2 - line1 type operation.

As I couldn't get this to work with real data, I wrote a tiny python program which logs in this format:

> [@](#):
>
> Date,Counter,Id,Total,RandomNumber,Phase  
> Thu Sep 3 10:15:39 2015,14912,2,0,668,START  
> Thu Sep 3 10:15:39 2015,14913,2,912,912,END  
> Thu Sep 3 10:15:40 2015,14914,3,0,931,START  
> Thu Sep 3 10:15:40 2015,14915,3,39,39,MIDDLE  
> Thu Sep 3 10:15:40 2015,14916,3,89,50,END  
> Thu Sep 3 10:15:41 2015,14917,6,0,180,START  
> Thu Sep 3 10:15:41 2015,14918,6,473,473,MIDDLE  
> Thu Sep 3 10:15:41 2015,14919,6,1289,816,MIDDLE  
> Thu Sep 3 10:15:41 2015,14920,6,2046,757,MIDDLE  
> Thu Sep 3 10:15:41 2015,14921,6,2868,822,MIDDLE  
> Thu Sep 3 10:15:41 2015,14922,6,3800,932,END

The idea now is compare what Logstash returns from the computation of agg\_total+=RandomNumber, with the value of Total.

This is the Exception I get when I try to start Logstash (1.5.2 or 1.5.3 )

```auto
Exception in filterworker {"exception"=>#<NoMethodError: undefined method `+' for nil:NilClass>, "backtrace"=>["(aggregate filter code):1:in `register'", "org/jruby/RubyProc.java:271:in `call'", "/Users/AnoBan/Elastic/logstash-1.5.2/vendor/bundle/jruby/1.9/gems/logstash-filter-aggregate-0.1.3/lib/logstash/filters/aggregate.rb:204:in `filter'", "org/jruby/ext/thread/Mutex.java:149:in `synchronize'", "/Users/AnoBan/Elastic/logstash-1.5.2/vendor/bundle/jruby/1.9/gems/logstash-filter-aggregate-0.1.3/lib/logstash/filters/aggregate.rb:191:in `filter'", "/Users/AnoBan/Elastic/logstash-1.5.2/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.2.2-java/lib/logstash/filters/base.rb:163:in `multi_filter'", "org/jruby/RubyArray.java:1613:in `each'", "/Users/AnoBan/Elastic/logstash-1.5.2/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.2.2-java/lib/logstash/filters/base.rb:160:in `multi_filter'", "(eval):428:in `cond_func_17'", "org/jruby/RubyArray.java:1613:in `each'", "(eval):425:in `cond_func_17'", "(eval):443:in `cond_func_16'", "org/jruby/RubyArray.java:1613:in `each'", "(eval):439:in `cond_func_16'", "(eval):474:in `cond_func_14'", "org/jruby/RubyArray.java:1613:in `each'", "(eval):469:in `cond_func_14'", "(eval):207:in `filter_func'", "/Users/AnoBan/Elastic/logstash-1.5.2/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.2.2-java/lib/logstash/pipeline.rb:218:in `filterworker'", "/Users/AnoBan/Elastic/logstash-1.5.2/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.2.2-java/lib/logstash/pipeline.rb:156:in `start_filters'"], :level=>:error}
```

* * *

This is my log stash Config:

* * *

```auto
input {

# Fake file for the Aggregate
  file {
    path => "/Users/AnoBan/Elastic/aggregator/*test"
    type => "aggregate"
  }
}

filter {
# if [type] == "system" {
# grok { 
# match => ["message" , "%{OSX}"]
# }
# }
    if [type] == "aggregate" {
        grok {
            match => ["message" , "%{GREEDYDATA},%{NOTSPACE:counter:int},%{NOTSPACE:id},%{NOTSPACE:total:int},%{NOTSPACE:random:int},%{NOTSPACE:key}"]
        }
        if [key] == "START" {
            mutate { add_tag => ["keyIsStart"] }
            aggregate {
                task_id => "%{id}"
                code => "map['total_value'] = 0"
                map_action => "create"
                add_tag => ["aggregateStart"]
            }
        }
        if [key] == "MIDDLE" {
            mutate { add_tag => ["keyIsMiddle"] }
            if [random] {
                aggregate {
                    task_id => "%{id}"
                    code => "map['total_value'] += event['random']"
                    add_tag => ["aggregateMiddle"]
                }
            }
        }
        if [key] == "END" {
            mutate { add_tag => ["keyIsEnd"] }
            aggregate {
                task_id => "%{id}"
                code => "event['agg_total'] = map['total_value']"
                end_of_task => true
                add_tag => ["aggregateEnd"]
            }
        }
    }
}

output {
    elasticsearch {
        host => "127.0.0.1"
        protocol => "transport"
    }
    stdout { codec => "rubydebug" }
}
```

---

<div class="post-metadata">

**Author:** ![anoban](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anoban/32/3466_2.png) [@anoban](https://discuss.elastic.co/u/anoban)\
**Post date:** [September 3, 2015, 8:28am UTC](https://discuss.elastic.co/t/cannot-get-the-aggregate-plugin-to-work/28570/2 "2015-09-03T08:28:18Z")

</div>

Adding

```auto

```

On middle and end blocks fixed the issue.

I was basically trying to run code on non existing maps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:30am UTC](https://discuss.elastic.co/t/cannot-get-the-aggregate-plugin-to-work/28570/3 "2017-07-06T05:30:16Z")

</div>


