# Get current bucket value in a Moving function agg

**URL:** <https://discuss.elastic.co/t/get-current-bucket-value-in-a-moving-function-agg/174034>\
**Category:** Elasticsearch\
**Created:** [March 27, 2019, 2:30am UTC](https://discuss.elastic.co/t/get-current-bucket-value-in-a-moving-function-agg/174034 "2019-03-27T02:30:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nuf](https://avatars.discourse-cdn.com/v4/letter/n/bbe5ce/32.png) [@nuf](https://discuss.elastic.co/u/nuf)\
**Post date:** [March 27, 2019, 2:30am UTC](https://discuss.elastic.co/t/get-current-bucket-value-in-a-moving-function-agg/174034/1 "2019-03-27T02:30:58Z")

</div>

Hi all,

I'm trying to calculate the year over year percentage change, which comes down to finding the percentage change of bucket values in a histogram.

I can use the derivative aggregation as discussed here to get the simple difference. But I don't think Bucket script agg could be used for this although it's suggested there.

> [@New to ES/Compare daily data to previous date's data](https://discuss.elastic.co/t/new-to-es-compare-daily-data-to-previous-dates-data/125392/4):
>
> Okay, it looks like abdon's suggestion to use the Derivative function was successful at showing the difference from one moment to the next (thank you again!). Now my question is if there's a way I can open up that function to more complex calculations. So whereas the function for derivative is a basic t(n+1) - t(n) (I THINK I wrote that right...), is there a way to access the function so that I could calculate other things (like a percentage change, for example)? In other words, right now Deriva…

Then I figured the new moving function aggregation is a great fit because I can use a window of 2 with a custom function.  
But the issue with that is, moving fn agg doesn't seem to consider the current bucket value as discussed in the following issue.

> <https://github.com/elastic/elasticsearch/issues/20667>
>
> I 'm using Elasticsearch 'Moving Average' in the pipeline aggregation to compute… the moving average of time series data, but I found the moving average is shifted one day . For example, when I set window = 3, i.e., 3 days moving average, I expect the moving average equals the average of the current day and previous 2 days, but the results are the average of previous 3 days, and not including the current day. The first bucket doesn't include any moving average value because of this.
> 
> Also, could you please consider add a 'Moving Standard deviation' in the future? It will be helpful for the statistical process control.
> 
> Here are my codes and results.
> 
> \`\`\`
> GET /tweets-classified\*/\_search
> {
> "size": 0,
> "query": {
> "filtered": {
> "query": {
> "query\_string": {
> "query": "(syndromes.GI: 2) AND (place.country\_code: CA)"
> }
> },
> "filter": {
> "range": {
> "@timestamp": {
> "gte": "2016-01-01"
> 
> }
> }
> }
> }
> },
> "aggs": {
> "daily\_count": {
> "date\_histogram": {
> "field": "@timestamp",
> "interval": "day"
> },
> "aggs": {
> "the\_sum": {
> "sum": {
> "field": "syndromes.GI"
> }
> },
> "mvavg": {
> "moving\_avg": {
> "buckets\_path": "the\_sum",
> "window": 3,
> "model": "simple"
> }
> }
> }
> }
> }
> }
> \`\`\`
> 
> \`\`\`
> {
> "took": 6470,
> "timed\_out": false,
> "\_shards": {
> "total": 96,
> "successful": 96,
> "failed": 0
> },
> "hits": {
> "total": 1940,
> "max\_score": 0,
> "hits": \[\]
> },
> "aggregations": {
> "daily\_count": {
> "buckets": \[
> {
> "key\_as\_string": "2016-01-01T00:00:00.000Z",
> "key": 1451606400000,
> "doc\_count": 10,
> "the\_sum": {
> "value": 20
> }
> },
> {
> "key\_as\_string": "2016-01-02T00:00:00.000Z",
> "key": 1451692800000,
> "doc\_count": 9,
> "the\_sum": {
> "value": 18
> },
> "mvavg": {
> "value": 20
> }
> },
> {
> "key\_as\_string": "2016-01-03T00:00:00.000Z",
> "key": 1451779200000,
> "doc\_count": 5,
> "the\_sum": {
> "value": 10
> },
> "mvavg": {
> "value": 19
> }
> },
> {
> "key\_as\_string": "2016-01-04T00:00:00.000Z",
> "key": 1451865600000,
> "doc\_count": 9,
> "the\_sum": {
> "value": 18
> },
> "mvavg": {
> "value": 16
> }
> },
> {
> "key\_as\_string": "2016-01-05T00:00:00.000Z",
> "key": 1451952000000,
> "doc\_count": 12,
> "the\_sum": {
> "value": 24
> },
> "mvavg": {
> "value": 15.333333333333334
> }
> },
> {
> "key\_as\_string": "2016-01-06T00:00:00.000Z",
> "key": 1452038400000,
> "doc\_count": 10,
> "the\_sum": {
> "value": 20
> },
> "mvavg": {
> "value": 17.333333333333332
> }
> },
> \`\`\`
> 
> .......

Although, moving fn supports scripting, the values array which is passed in contains only the bucket values prior to the current bucket as shown in the following example. The values array length is always 1 less than the bucket count.

```
GET /demand/_search?typed_keys
{
  "size": 0,
  "aggs": {
    "by_qtr": {
      "histogram": {
        "field": "fiscal_quarter_year",
        "interval": 1,
        "min_doc_count": 1
      },
      "aggs": {
        "b_sum": {
          "sum": {
            "field": "qty"
          }
        },
        "movfn": {
          "moving_fn": {
            "buckets_path": "b_sum",
            "window": 2,
            "script": "return values.length"
          }
        }
      }
    }
  }
}

```

Response -

```
  "aggregations" : {
    "histogram#by_qtr" : {
      "buckets" : [
        {
          "key" : 201801.0,
          "doc_count" : 781,
          "sum#b_sum" : {
            "value" : 8156.0
          },
          "simple_value#movfn" : {
            "value" : 0.0
          }
        },
        {
          "key" : 201802.0,
          "doc_count" : 309,
          "sum#b_sum" : {
            "value" : 2460.0
          },
          "simple_value#movfn" : {
            "value" : 1.0
          }
        }
      ]
    }
  }

```

Ideally I should be able to use a moving function like following with some size checks  
"movfn": {  
"moving\_fn": {  
"buckets\_path": "b\_sum",  
"window": 2,  
"script": "return (values[1] / values[0]) - 1"  
}  
}

So is there any way to get the current bucket value in a moving function agg or is there another way to implement this requirement?

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2019, 2:35am UTC](https://discuss.elastic.co/t/get-current-bucket-value-in-a-moving-function-agg/174034/2 "2019-04-24T02:35:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
