# ES 6.3.2 Rollup avg metric does a sum instead?

**URL:** <https://discuss.elastic.co/t/es-6-3-2-rollup-avg-metric-does-a-sum-instead/146875>\
**Category:** Elasticsearch\
**Created:** [August 31, 2018, 2:10pm UTC](https://discuss.elastic.co/t/es-6-3-2-rollup-avg-metric-does-a-sum-instead/146875 "2018-08-31T14:10:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ld\_pvl](https://avatars.discourse-cdn.com/v4/letter/l/cdc98d/32.png) [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Post date:** [August 31, 2018, 2:10pm UTC](https://discuss.elastic.co/t/es-6-3-2-rollup-avg-metric-does-a-sum-instead/146875/1 "2018-08-31T14:10:34Z")

</div>

Hi Team,

I think either there is a bug or I'm doing something silly.

This is my rollup job `GET /_xpack/rollup/job/my-job/?pretty`:

```
{
  "jobs" : [
    {
      "config" : {
        "id" : "my-job",
        "index_pattern" : "my pattern",
        "rollup_index" : "my rollup index",
        "cron" : "0 * * * * ?",
        "groups" : {
          "date_histogram" : {
            "interval" : "10m",
            "field" : "@timestamp",
            "delay" : "2d",
            "time_zone" : "UTC"
          },
          "terms" : {
            "fields" : [
              "grid_instance",
              "host",
              "host_data_center",
              "host_region"
            ]
          }
        },
        "metrics" : [
          {
            "field" : "temperature",
            "metrics" : [
              "min",
              "max",
              "avg"
            ]
          },
          {
            "field" : "memory_used_MB",
            "metrics" : [
              "min",
              "max",
              "avg"
            ]
          },
          {
            "field" : "power_draw_W",
            "metrics" : [
              "min",
              "max",
              "avg"
            ]
          },
          {
            "field" : "utilization_gpu_percent",
            "metrics" : [
              "min",
              "max",
              "avg"
            ]
          }
        ],
        "timeout" : "20s",
        "page_size" : 100000
      },

      ... ETC ...

    }
  ]
}

```

But I can see the aggregated value for `avg` looks like a sum?

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/371800b8e4ec86aed797664893ab2dd34625e479.png)

Am I doing something wrong?

Thanks for your help,

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [August 31, 2018, 2:54pm UTC](https://discuss.elastic.co/t/es-6-3-2-rollup-avg-metric-does-a-sum-instead/146875/2 "2018-08-31T14:54:40Z")

</div>

Nope, you're doing everything correct! That's how Rollup represents averages internally. You'll notice there is both a value and a count for each average field. E.g.

```auto
memory_used_MB.avg._count
memory_used_MB.avg.value

```

At query time, we use the count and value (which is really a sum as you noticed) to rebuild the average (`sum / count == average`).

We do this because we want to allow averages over any interval greater-than-or-equal to the configured interval. [Averaging averages together is a bad idea](https://wattsupwiththat.com/2017/07/24/the-laws-of-averages-part-3-the-average-average/), so we store the sum + count instead which gives us interval freedom. We can just sum up the sums, sum up the counts, _then_ perform the average as required.

That's part of the reason there's a separate `_rollup_search` endpoint, we do these sort of gymnastics behind the scenes so the user doesn't need to think about it 🙂

---

<div class="post-metadata">

**Author:** ![ld\_pvl](https://avatars.discourse-cdn.com/v4/letter/l/cdc98d/32.png) [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Post date:** [August 31, 2018, 3:04pm UTC](https://discuss.elastic.co/t/es-6-3-2-rollup-avg-metric-does-a-sum-instead/146875/3 "2018-08-31T15:04:57Z")

</div>

Many thanks, it makes total sense now. Great new feature.

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [August 31, 2018, 9:04pm UTC](https://discuss.elastic.co/t/es-6-3-2-rollup-avg-metric-does-a-sum-instead/146875/4 "2018-08-31T21:04:33Z")

</div>

Happy to help! Thanks for trying out Rollup! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2018, 9:07pm UTC](https://discuss.elastic.co/t/es-6-3-2-rollup-avg-metric-does-a-sum-instead/146875/5 "2018-09-28T21:07:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
