# Create new aggregation index periodically

**URL:** <https://discuss.elastic.co/t/create-new-aggregation-index-periodically/245999>\
**Category:** Elasticsearch\
**Created:** [August 22, 2020, 10:50pm UTC](https://discuss.elastic.co/t/create-new-aggregation-index-periodically/245999 "2020-08-22T22:50:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vester](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vester/32/81160_2.png) [@Vester](https://discuss.elastic.co/u/Vester)\
**Post date:** [August 22, 2020, 10:50pm UTC](https://discuss.elastic.co/t/create-new-aggregation-index-periodically/245999/1 "2020-08-22T22:50:45Z")

</div>

Hi,

I'm trying to create periodically a new index based on aggregation, something like:

"size": 0,  
"aggs": {  
"group\_by\_xpto": {  
"terms": {  
"field": "xpto.keyword",  
"size": 10000  
},  
"aggs": {  
"latest\_position": {  
"max": {  
"field": "PositionX"  
}  
},  
"include\_source": {  
"top\_hits": {  
"size": 1,  
"\_source": {  
"includes": [  
"Field1","Field2","Field3"  
]  
}  
}  
}  
}  
}  
}  
}

I tried several approaches, Rollup jobs, Transformations, but none seems to support the type of aggregation I need. The last attempt was using Logstash with a schedule input and output, but it seems that aggregations are not supported, [https://github.com/logstash-plugins/logstash-input-elasticsearch/issues/58](https://github.com/logstash-plugins/logstash-input-elasticsearch/issues/58) .  
Can someone suggest a solution or the best approach ?

thanks

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 22, 2020, 10:53pm UTC](https://discuss.elastic.co/t/create-new-aggregation-index-periodically/245999/2 "2020-08-22T22:53:09Z")

</div>

You can [aggregate in Logstash filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html). Might be worth checking out to see if it can work for this use case.

---

<div class="post-metadata">

**Author:** ![Vester](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vester/32/81160_2.png) [@Vester](https://discuss.elastic.co/u/Vester)\
**Post date:** [August 23, 2020, 9:08pm UTC](https://discuss.elastic.co/t/create-new-aggregation-index-periodically/245999/3 "2020-08-23T21:08:10Z")

</div>

Thanks for your suggestion, I read the documentation for the filter, it seems a bit confusing, but I'll give it a try. If you have a link with some more working examples, please let me know.

thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2020, 9:08pm UTC](https://discuss.elastic.co/t/create-new-aggregation-index-periodically/245999/4 "2020-09-20T21:08:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
