Doubt regarding aggregation of metrics which are read from log files

I have a very trivial doubt, when i read log files and send this to elasticsearch via filebeat and logstash, sp while doing aggregations and performing operations like sum, average does it read the log file before aggregating it or it has created a time series graph for itself and then present the data?

the contents of a log file are stored in elasticsearch for effecient retrieval of those aggregations, thus the original log file is not needed to execute an aggregation, as all the data is already within Elasticsearch.