# Filtering documents for rollup

**URL:** <https://discuss.elastic.co/t/filtering-documents-for-rollup/167417>\
**Category:** Kibana\
**Created:** [February 7, 2019, 10:13am UTC](https://discuss.elastic.co/t/filtering-documents-for-rollup/167417 "2019-02-07T10:13:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![slabajos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/slabajos/32/38171_2.png) [@slabajos](https://discuss.elastic.co/u/slabajos)\
**Post date:** [February 7, 2019, 10:13am UTC](https://discuss.elastic.co/t/filtering-documents-for-rollup/167417/1 "2019-02-07T10:13:15Z")

</div>

I've been testing the rollup feature and I like it, a lot, cause it is something we wanted to do manually but never found the time to implement it. It is simple, easy and can save tons of space. The problem is that it is very limited.  
Let's say we have API requests on ElasticSearch, and we have a "status" field with the HTTP response status code. I can configure the rollup job to include this field for terms aggregation but I find it frustrating that I cannot query the rollup index with q="status:200" for example. I mean, the data is there! Why can't I filter?

Ok ok, I know it is in beta, and I know it is tricky. Cause at some point I will want to query by status and URL too, for example. And storing all the field combinations in a single rollup index would not scale well I guess.

I have an idea I would like to share with you, please let me know if it makes any sense or not:

 ![rollup-filter-idea](https://us1.discourse-cdn.com/elastic/original/3X/e/f/efd9d546851e4833f9fcc986f332b440b0f1491d.png)  
Instead of filtering data after the rollup job has aggregated everything, can we filter it when doing the rollup? Is this very difficult to implement?  
It would be very useful, at least for me. I could have a rollup for errors, a global rollup for all traffic, maybe a rollup for a specific endpoint I want to track over time, or a rollup for requests that take longer than X ms to respond... Much more powerful, don't know what you think.

Anyways, thanks for reading and thanks for the rollup feature, I think it has a lot of potential!

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [February 7, 2019, 10:25am UTC](https://discuss.elastic.co/t/filtering-documents-for-rollup/167417/2 "2019-02-07T10:25:27Z")

</div>

@timroes @jen-huang

---

<div class="post-metadata">

**Author:** ![jen-huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jen-huang/32/74327_2.png) [@jen-huang](https://discuss.elastic.co/u/jen-huang)\
**Post date:** [February 12, 2019, 10:55pm UTC](https://discuss.elastic.co/t/filtering-documents-for-rollup/167417/3 "2019-02-12T22:55:34Z")

</div>

I think this is an interesting suggestion and recommend filing an enhancement request in the Elasticsearch repo, as it is ES, not Kibana, that does all the heavy lifting of processing rollup jobs: [https://github.com/elastic/elasticsearch/issues](https://github.com/elastic/elasticsearch/issues)

---

<div class="post-metadata">

**Author:** ![slabajos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/slabajos/32/38171_2.png) [@slabajos](https://discuss.elastic.co/u/slabajos)\
**Post date:** [February 13, 2019, 9:55am UTC](https://discuss.elastic.co/t/filtering-documents-for-rollup/167417/4 "2019-02-13T09:55:41Z")

</div>

Done! [https://github.com/elastic/elasticsearch/issues/38837](https://github.com/elastic/elasticsearch/issues/38837)  
Thank you both, I hope we can see this implemented at some point 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2019, 10:11am UTC](https://discuss.elastic.co/t/filtering-documents-for-rollup/167417/5 "2019-03-13T10:11:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
