# Certain question on rollups

**URL:** <https://discuss.elastic.co/t/certain-question-on-rollups/234048>\
**Category:** Elasticsearch\
**Created:** [May 24, 2020, 2:58pm UTC](https://discuss.elastic.co/t/certain-question-on-rollups/234048 "2020-05-24T14:58:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yannis\_Psarras](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yannis_psarras/32/68945_2.png) [@Yannis\_Psarras](https://discuss.elastic.co/u/Yannis_Psarras)\
**Post date:** [May 24, 2020, 2:58pm UTC](https://discuss.elastic.co/t/certain-question-on-rollups/234048/1 "2020-05-24T14:58:50Z")

</div>

Hey all,

I have a few questions on rollup jobs. Mind that we are new to ES so please bear with me.

1.I wanted to understand the effect of settings certain index fields to index: false when there are certain rollup jobs that aggregate against those fields.  
Example: field: cpu\_time set to index = false. Can I create a rollup job that aggregates to average cpu\_time per hour?

1. Can I set field names for rollup indices? Like in the example above. Can I set the name of the average cpu\_time somehow.

Thanks  
Y

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2020, 1:02am UTC](https://discuss.elastic.co/t/certain-question-on-rollups/234048/2 "2020-05-25T01:02:07Z")

</div>

Welcome! 😃

1. Not indexing a field means it won't be searched against, which won't impact a rollup.
2. Good question! You could try specifying a mapping (or template) and then applying an [`alias`](https://www.elastic.co/guide/en/elasticsearch/reference/current/alias.html). I haven't tried it though, so that's more an educated guess.

---

<div class="post-metadata">

**Author:** ![Yannis\_Psarras](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yannis_psarras/32/68945_2.png) [@Yannis\_Psarras](https://discuss.elastic.co/u/Yannis_Psarras)\
**Post date:** [May 25, 2020, 4:55am UTC](https://discuss.elastic.co/t/certain-question-on-rollups/234048/3 "2020-05-25T04:55:52Z")

</div>

Hi Mark

Thanks a lot for taking the time to answer my questions!

Let me elaborate a bit on my second question and explain why an alias won't work. I have two indices of raw data. I want to aggregate data from these indexes into a roll-up index.

Example:

Index 1: pageviews (website, page, timestamp)  
Index 2: purchases (website, product, timestamp)

These above indexes have hundreds of thousands of events a day

I want to create a roll-up with one document per website per dat

website\_totals (website, timestamp, first\_pageview, last\_pageview, total\_pageviews, first\_purchase, last\_purchase, total\_purchases)

The complexity for me comes because the total\_pageviews and total\_purchases fields are derived using the same formula on the same field but on different indexes (count of timestamp). If I am not able to name them differently like in my example one will end up overwriting the other

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2020, 5:09am UTC](https://discuss.elastic.co/t/certain-question-on-rollups/234048/4 "2020-05-25T05:09:46Z")

</div>

Ahh ok. Why do you want them in a single index?

---

<div class="post-metadata">

**Author:** ![Yannis\_Psarras](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yannis_psarras/32/68945_2.png) [@Yannis\_Psarras](https://discuss.elastic.co/u/Yannis_Psarras)\
**Post date:** [May 25, 2020, 5:24am UTC](https://discuss.elastic.co/t/certain-question-on-rollups/234048/5 "2020-05-25T05:24:33Z")

</div>

Cause we commonly query all these things together and two queries sounded like an overkill.

Maybe too used to sql DBA ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2020, 5:27am UTC](https://discuss.elastic.co/t/certain-question-on-rollups/234048/6 "2020-05-25T05:27:15Z")

</div>

> [@Yannis\_Psarras](#):
>
> Maybe too used to sql DBA ?

Heh, that's a pretty succinct summary tbh. I wouldn't even worry about it.

And even if they're in separate indices, you can still [query them both](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-index.html) at the same time, eg "show me all stats in this timeframe".

---

<div class="post-metadata">

**Author:** ![Yannis\_Psarras](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yannis_psarras/32/68945_2.png) [@Yannis\_Psarras](https://discuss.elastic.co/u/Yannis_Psarras)\
**Post date:** [May 25, 2020, 5:55am UTC](https://discuss.elastic.co/t/certain-question-on-rollups/234048/7 "2020-05-25T05:55:38Z")

</div>

Thanks Mark

You are super helpful!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2020, 5:55am UTC](https://discuss.elastic.co/t/certain-question-on-rollups/234048/8 "2020-06-22T05:55:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
