# Getting sum from elasticsearch query

**URL:** <https://discuss.elastic.co/t/getting-sum-from-elasticsearch-query/88195>\
**Category:** Elasticsearch\
**Created:** [June 4, 2017, 3:50pm UTC](https://discuss.elastic.co/t/getting-sum-from-elasticsearch-query/88195 "2017-06-04T15:50:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![procipher](https://avatars.discourse-cdn.com/v4/letter/p/aeb1de/32.png) [@procipher](https://discuss.elastic.co/u/procipher)\
**Post date:** [June 4, 2017, 3:50pm UTC](https://discuss.elastic.co/t/getting-sum-from-elasticsearch-query/88195/1 "2017-06-04T15:50:41Z")

</div>

I have elasticsearch query output in format like this:

```
{
      "_index" : "logstash-2017.06.04",
      "_type" : "nginx_log",
      "_id" : "AVxzT8gGkcEbrbfVdHEU",
      "_score" : null,
      "_source" : {
         "method" : "GET",
        "path" : "",
        "code" : "200",
        "size" : "396",
        "request_time" : "0.000",
        "referer" : "-",
        "agent" : "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36",
        "@timestamp" : "2017-06-04T13:30:37+00:00"
      },
      "sort" : [1496583037000]
    }

```

Now I want to get the sum of "size" key. Is it possible from elasticsearch query?

PS: the complete query result looks like this: [https://pastebin.com/raw/8aPiAb1V](https://pastebin.com/raw/8aPiAb1V)

Thanks.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 4, 2017, 4:47pm UTC](https://discuss.elastic.co/t/getting-sum-from-elasticsearch-query/88195/2 "2017-06-04T16:47:47Z")

</div>

First, change the mapping to make that field a number. Then reindex.  
Add a sum agg on field size.

---

<div class="post-metadata">

**Author:** ![procipher](https://avatars.discourse-cdn.com/v4/letter/p/aeb1de/32.png) [@procipher](https://discuss.elastic.co/u/procipher)\
**Post date:** [June 5, 2017, 5:43am UTC](https://discuss.elastic.co/t/getting-sum-from-elasticsearch-query/88195/3 "2017-06-05T05:43:52Z")

</div>

Can you please guide me a bit? Thanks

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 29, 2017, 3:30pm UTC](https://discuss.elastic.co/t/getting-sum-from-elasticsearch-query/88195/4 "2017-06-29T15:30:48Z")

</div>

Here we go:

```auto
DELETE test
PUT test
{
  "mappings": {
    "doc": {
      "properties": {
        "foo": {
          "type": "integer"
        }
      }
    }
  }
}
PUT test/doc/1
{
  "foo": 1
}
PUT test/doc/2
{
  "foo": 2
}
GET test/_search
{
  "size": 0,
  "aggs": {
    "sum_of_foo": {
      "sum": {
        "field": "foo"
      }
    }
  }
}

```

To reindex, have a look at: [https://www.elastic.co/guide/en/elasticsearch/reference/5.4/docs-reindex.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/docs-reindex.html)

Do something like:

```auto
POST _reindex
{
  "source": {
    "index": "logstash-2017.06.04"
  },
  "dest": {
    "index": "test"
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2017, 3:30pm UTC](https://discuss.elastic.co/t/getting-sum-from-elasticsearch-query/88195/5 "2017-07-27T15:30:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
