# Elasticsearch aggregation on object over time series

**URL:** <https://discuss.elastic.co/t/elasticsearch-aggregation-on-object-over-time-series/43566>\
**Category:** Elasticsearch\
**Created:** [March 5, 2016, 2:38am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-on-object-over-time-series/43566 "2016-03-05T02:38:57Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bstsnail](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@bstsnail](https://discuss.elastic.co/u/bstsnail)\
**Post date:** [March 5, 2016, 2:38am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-on-object-over-time-series/43566/1 "2016-03-05T02:38:57Z")

</div>

I have the following document in Elasticsearch  
`{"timestamp": 1457018658303, "location": {"lat":1, "lon":1}} {"timestamp": 1457018718303, "location": {"lat":2, "lon":2}} {"timestamp": 1457018778303, "location": {"lat":3, "lon":3}} {"timestamp": 1457018838303, "location": {"lat":4, "lon":4}} {"timestamp": 1457018898303, "location": {"lat":5, "lon":5}} {"timestamp": 1457018958303, "location": {"lat":6, "lon":6}}`

and the mapping is:  
`{ "mappings": { "test": { "_all":{ "enabled": false }, "_source": { "enabled": false }, "properties": { "timestamp": { "type": "date", "format": "epoch_millis", "doc_values": true }, "location": { "properties": { "lat": {"type": "double", "index": "no", "doc_values": true}, "lon": {"type": "double", "index": "no", "doc_values": true} } } } }`  
Assume that the timestamp interval is 1 minute in the Elasticsearch. So if I want to do the date\_histogram on timestamp and the interval is 5 minutes, and pick the first record of location every 5 minutes So the aggregation result should like this  
`{ "aggregations": { "buckets": [ { "timestamp":1457018658303, "location.lat":1, "location.lon":1 }, { "timestamp":1457018898303, "location.lat":5, "location.lon":5 }, } }`

Can I aggregation like this ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 5, 2016, 3:30am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-on-object-over-time-series/43566/2 "2016-03-05T03:30:17Z")

</div>

Try with a date\_histogram agg and add within it a top\_hits agg with size=1.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-top-hits-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-top-hits-aggregation.html)

---

<div class="post-metadata">

**Author:** ![bstsnail](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@bstsnail](https://discuss.elastic.co/u/bstsnail)\
**Post date:** [March 5, 2016, 3:56am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-on-object-over-time-series/43566/3 "2016-03-05T03:56:52Z")

</div>

Thanks dadoonet,  
I have tried that already,  
but as I have disable the \_source field, so the result will be like this  
`"aggregations": { "result": { "buckets": [{ "key_as_string": "2016-02-27T15:20:00.000Z", "key": 1456586400000, "doc_count": 4, "hits": { "hits": { "total": 4, "max_score": 1, "hits": [ { "_index": "geoindex13", "_type": "geotype13", "_id": "998", "_score": 1 }] } } }, ...`  
Just can get the index id, , can't get the location.lat and location.lon.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 5, 2016, 8:57am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-on-object-over-time-series/43566/4 "2016-03-05T08:57:57Z")

</div>

And did you store the lat and lon fields?

PS: you should disable source only if you have a very good reason doing it. You won't be able to use the new reindex API without the source for example.

---

<div class="post-metadata">

**Author:** ![bstsnail](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@bstsnail](https://discuss.elastic.co/u/bstsnail)\
**Post date:** [March 5, 2016, 9:15am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-on-object-over-time-series/43566/5 "2016-03-05T09:15:12Z")

</div>

Yes, I did.  
The sample data like this:  
`{"timestamp": 1457018658303, "location": {"lat":1, "lon":1}} {"timestamp": 1457018718303, "location": {"lat":2, "lon":2}} {"timestamp": 1457018778303, "location": {"lat":3, "lon":3}} {"timestamp": 1457018838303, "location": {"lat":4, "lon":4}} {"timestamp": 1457018898303, "location": {"lat":5, "lon":5}} {"timestamp": 1457018958303, "location": {"lat":6, "lon":6}}`  
And I disable source because I want to store the time series data, and will not be reindex any more and just want to data to be aggregation.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 5, 2016, 9:41am UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-on-object-over-time-series/43566/6 "2016-03-05T09:41:44Z")

</div>

May be script\_fields can help?

[https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-script-fields.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-script-fields.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:11pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-on-object-over-time-series/43566/7 "2017-07-05T23:11:01Z")

</div>


