# Getting two intervals in the result for fixed\_interval

**URL:** <https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754>\
**Category:** Elasticsearch\
**Created:** [September 20, 2022, 8:43am UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754 "2022-09-20T08:43:54Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Divin](https://avatars.discourse-cdn.com/v4/letter/d/f475e1/32.png) [@Divin](https://discuss.elastic.co/u/Divin)\
**Post date:** [September 20, 2022, 8:43am UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754/1 "2022-09-20T08:43:54Z")

</div>

I have an ES query that search for 2 set of strings and calculating percentage based on the results of the match. This is expected to have work on fixed\_interval [5 min]on date histogram. But when I am getting the result but I see two 5 min interval where it should be last 5 mins. Can you please help me here to get fixed interval of 5min .

```auto
GET index_*/_search
 {
          "query": {
            "bool": {
              "must": [
                {
                  "query_string": {
                    "fields": [
                      "message"
                    ],
                    "query": """
                    ("::search result found." OR "::search result not found.")
                    """
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-5m",
                      "lte": "now"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
            "latest": {
              "date_histogram": {
                "field": "@timestamp",
                "fixed_interval": "5m"
              },
              "aggs": {
                "calculation": {
                  "filters": {
                    "filters": {
                      "total": {
                        "match_phrase": {
                          "message": """
                            "::search result found." 
                            """}
                      }
                    }
                  }
                },
                "calculation1": {
                  "filters": {
                    "filters": {
                      "fail": {
                        "match_phrase": {
                          "message": """
                                "::search result not found." 
                                """
                        }
                      }
                    }
                  }
                },
                "total": {
                  "sum_bucket": {
                    "buckets_path": "calculation>_count"
                  }
                },
                "fail": {
                  "sum_bucket": {
                    "buckets_path": "calculation1>_count"
                  }
                },
                "percentage": {
                  "bucket_script": {
                    "buckets_path": {
                      "totals": "total",
                      "fails": "fail"
                    },
                    "script": "params.fails / params.totals*100"
                  }
                }
              }
            }
          }
 }

```

Result

```auto
  "aggregations" : {
    "latest" : {
      "buckets" : [
        {
          "key_as_string" : "2022-09-20T08:00:00.000Z",
          "key" : 1663660800000,
          "doc_count" : 4,
          "calculation" : {
            "buckets" : {
              "total" : {
                "doc_count" : 4
              }
            }
          },
          "calculation1" : {
            "buckets" : {
              "fail" : {
                "doc_count" : 0
              }
            }
          },
          "total" : {
            "value" : 4.0
          },
          "fail" : {
            "value" : 0.0
          },
          "percentage" : {
            "value" : 0.0
          }
        },
        {
          "key_as_string" : "2022-09-20T08:05:00.000Z",
          "key" : 1663662600000,
          "doc_count" : 1,
          "calculation" : {
            "buckets" : {
              "total" : {
                "doc_count" : 1
              }
            }
          },
          "calculation1" : {
            "buckets" : {
              "fail" : {
                "doc_count" : 0
              }
            }
          },
          "total" : {
            "value" : 1.0
          },
          "fail" : {
            "value" : 0.0
          },
          "percentage" : {
            "value" : 0.0
          }
        }
      ]
    }
  }
}

```

Expected Result

```auto
  "aggregations" : {
    "latest" : {
      "buckets" : [
        {
          "key_as_string" : "2022-09-20T08:00:00.000Z",
          "key" : 1663660800000,
          "doc_count" : 4,
          "calculation" : {
            "buckets" : {
              "total" : {
                "doc_count" : 4
              }
            }
          },
          "calculation1" : {
            "buckets" : {
              "fail" : {
                "doc_count" : 0
              }
            }
          },
          "total" : {
            "value" : 4.0
          },
          "fail" : {
            "value" : 0.0
          },
          "percentage" : {
            "value" : 0.0
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 21, 2022, 1:20am UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754/2 "2022-09-21T01:20:21Z")

</div>

Welcome to our community! 😃

Just to be clear, are you referring to the difference between these two?

> [@Divin](#):
>
> `"key_as_string" : "2022-09-20T08:00:00.000Z",`

> [@Divin](#):
>
> `"key_as_string" : "2022-09-20T08:05:00.000Z",`

---

<div class="post-metadata">

**Author:** ![Divin](https://avatars.discourse-cdn.com/v4/letter/d/f475e1/32.png) [@Divin](https://discuss.elastic.co/u/Divin)\
**Post date:** [September 22, 2022, 7:18am UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754/3 "2022-09-22T07:18:12Z")

</div>

Yes. If you can see in my query I have a fixed interval of 5 mins. But I see two intervals

```auto
"key_as_string" : "2022-09-20T08:00:00.000Z",

```

```auto
"key_as_string" : "2022-09-20T08:05:00.000Z",

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 22, 2022, 7:23am UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754/4 "2022-09-22T07:23:00Z")

</div>

The date histogram aligns buckets based on 5 minute intervals since epoch and since your `now` is not exactly such a timestamp your date histogram straddles two buckets.

---

<div class="post-metadata">

**Author:** ![Divin](https://avatars.discourse-cdn.com/v4/letter/d/f475e1/32.png) [@Divin](https://discuss.elastic.co/u/Divin)\
**Post date:** [September 26, 2022, 7:16am UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754/5 "2022-09-26T07:16:23Z")

</div>

Can you suggest me how can I get last 5 minuets with range query to make sure date histogram doesn't straddles two buckets.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 26, 2022, 7:40am UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754/6 "2022-09-26T07:40:21Z")

</div>

If you are querying an interval of 5 minutes and want all a single interval, why use a date histogram at all?

---

<div class="post-metadata">

**Author:** ![Divin](https://avatars.discourse-cdn.com/v4/letter/d/f475e1/32.png) [@Divin](https://discuss.elastic.co/u/Divin)\
**Post date:** [September 26, 2022, 8:20am UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754/7 "2022-09-26T08:20:38Z")

</div>

Without data histogram , we are not able to perform aggregation. Followed this [Pipeline aggregations | Elasticsearch Guide [8.4] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline.html#buckets-path-syntax)

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "parsing_exception",
        "reason" : "Unknown aggregation type [calculation]",
        "line" : 27,
        "col" : 32
      }
    ],
    "type" : "parsing_exception",
    "reason" : "Unknown aggregation type [calculation]",
    "line" : 27,
    "col" : 32,
    "caused_by" : {
      "type" : "named_object_not_found_exception",
      "reason" : "[27:32] unknown field [calculation]"
    }
  },
  "status" : 400
}

```

---

<div class="post-metadata">

**Author:** ![Divin](https://avatars.discourse-cdn.com/v4/letter/d/f475e1/32.png) [@Divin](https://discuss.elastic.co/u/Divin)\
**Post date:** [October 3, 2022, 6:05pm UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754/8 "2022-10-03T18:05:22Z")

</div>

@Christian_Dahlqvist Any suggestions??

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2022, 6:05pm UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754/9 "2022-10-31T18:05:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
