# Elasticsearch sub agregation

**URL:** <https://discuss.elastic.co/t/elasticsearch-sub-agregation/292920>\
**Category:** Elasticsearch\
**Created:** [December 25, 2021, 6:18pm UTC](https://discuss.elastic.co/t/elasticsearch-sub-agregation/292920 "2021-12-25T18:18:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Time\_cool](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/time_cool/32/99532_2.png) [@Time\_cool](https://discuss.elastic.co/u/Time_cool)\
**Post date:** [December 25, 2021, 6:18pm UTC](https://discuss.elastic.co/t/elasticsearch-sub-agregation/292920/1 "2021-12-25T18:18:12Z")

</div>

With the following query, I get the minimum value in each chunk of 15 minutes. I use the moving\_fn function. Now I need to get the maximum value in each chunk in 1 hour from the previous request. As I understand it cannot be used for aggregation after moving\_fn. How can you do this?

This is my query:

```auto
GET logstash-2021.12.2*/_search 
{ 
  "query": { 
    "bool": { 
      "filter": [ 
        { 
          "range": { 
            "@timestamp": { 
              "gte": "now-24h" 
            } 
          } 
        }, 
        { 
          "bool": { 
            "should": [ 
              { 
                "match_phrase": { 
                  "company": "BLAH-BLAH" 
                } 
              }
            ] 
          } 
        } 
      ] 
    } 
  },
  "size": 0,
  "aggs": {
    "myDatehistogram": {
      "date_histogram": {
        "field": "@timestamp",
        "interval": "1m",
        "offset": "+30s"
      }, "aggs": {
        "the_count": {
          "moving_fn": {
            "buckets_path": "_count",
            "window": 15,
            "script": "MovingFunctions.min(values)"
          }
        }
      }
    }
   }
}

```

My response:

```auto
"aggregations" : {
    "myDatehistogram" : {
      "buckets" : [
        {
          "key_as_string" : "2021-12-25T05:58:30.000Z",
          "key" : 1640411910000,
          "doc_count" : 1196,
          "the_count" : {
            "value" : null
          }
        },
        {
          "key_as_string" : "2021-12-25T05:59:30.000Z",
          "key" : 1640411970000,
          "doc_count" : 1942,
          "the_count" : {
            "value" : 1196.0
          }
        },
        {
          "key_as_string" : "2021-12-25T06:00:30.000Z",
          "key" : 1640412030000,
          "doc_count" : 1802,
          "the_count" : {
            "value" : 1196.0
          }
        },
        {
          "key_as_string" : "2021-12-25T06:01:30.000Z",
          "key" : 1640412090000,
          "doc_count" : 1735,
          "the_count" : {
            "value" : 1196.0
          }
        },
        {
          "key_as_string" : "2021-12-25T06:02:30.000Z",
          "key" : 1640412150000,
          "doc_count" : 1699,
          "the_count" : {
            "value" : 1196.0
          }
        },
        {
          "key_as_string" : "2021-12-25T06:03:30.000Z",
          "key" : 1640412210000,
          "doc_count" : 1506,
          "the_count" : {
            "value" : 1196.0
          }
        }

```

From this answer, I need to get the maximum value for each hour. Thank you in advance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 22, 2022, 6:18pm UTC](https://discuss.elastic.co/t/elasticsearch-sub-agregation/292920/2 "2022-01-22T18:18:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
