# How to aggregate data by an field?

**URL:** <https://discuss.elastic.co/t/how-to-aggregate-data-by-an-field/64296>\
**Category:** Elasticsearch\
**Created:** [October 28, 2016, 1:56pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-by-an-field/64296 "2016-10-28T13:56:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [October 28, 2016, 1:56pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-by-an-field/64296/1 "2016-10-28T13:56:52Z")

</div>

Hello,  
I'm using kibana 4.4.1 and in elasticsearch I store the status of PC, only when PC status is changed (open, closed, warings, etc)

My data into Elasticsearch looks like:  
{ "status\_id":1 , "pc":"lpt001" , "date":"2016-10-25T17:49:00Z" }  
{ "status\_id":3 , "pc":"lpt001" , "date":"2016-10-25T15:48:00Z" }  
{ "status\_id":4 , "pc":"lpt002" , "date":"2016-10-25T15:46:00Z" }  
{ "status\_id":1 , "pc":"lpt002" , "date":"2016-10-25T12:48:00Z" }

And I what to get the newest record in order to have at any time how many PC's are opened, closed or have some issues.  
My query is like:

> ```
> GET cb-2016.10.26/_search
> {
> "query": {
> "match_all": { }
> },
> "sort": [
> {
> "date": {
> "order": "desc"
> }
> }
> ], 
> "aggs": {
> "max_date":{
> "max": {
> "field": "date"
> }
> }
> }
> }
> 
> ```

And the result is:

```
"aggregations": {
    "max_date": {
      "value": 1477417680000,
      "value_as_string": "2016-10-25T17:48:00.000Z"
    }
  }

```

But What I want is to have that max\_date for each "pc": "lpt001", "lpt002".

There is any way to split max\_date by "pc" field? I read something about bucket aggregations but I did not reach the result.

Thank you,  
Ovidiu

---

<div class="post-metadata">

**Author:** ![ywelsch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ywelsch/32/7751_2.png) [@ywelsch](https://discuss.elastic.co/u/ywelsch)\
**Post date:** [October 28, 2016, 2:26pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-by-an-field/64296/2 "2016-10-28T14:26:21Z")

</div>

If I understand correctly, you want the latest entry for each PC. This can be achieved with the following query:

```auto
{
  "query": {
    "match_all": { }
  },
  "aggs" : {
        "pcstatus" : {
            "terms" : {
                "field" : "pc"
            },
            "aggs": {
                "top_date_hit": {
                    "top_hits": {
                        "sort": [
                            {
                                "date": {
                                    "order": "desc"
                                }
                            }
                        ],
                        "size" : 1
                    }
                }
            }
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [October 28, 2016, 2:47pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-by-an-field/64296/3 "2016-10-28T14:47:32Z")

</div>

yes,  
you're right!

when I run this into sense it works as I expected.

But there is any way to integrate it into kibana? Because the final target is to make a pie with this data. 🙂

---

<div class="post-metadata">

**Author:** ![ywelsch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ywelsch/32/7751_2.png) [@ywelsch](https://discuss.elastic.co/u/ywelsch)\
**Post date:** [October 28, 2016, 3:12pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-by-an-field/64296/4 "2016-10-28T15:12:31Z")

</div>

As far as I know the top\_hits aggregation cannot be used in Kibana. Maybe ask on the Kibana forum?

---

<div class="post-metadata">

**Author:** ![djvidov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djvidov/32/6135_2.png) [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Post date:** [October 28, 2016, 3:20pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-by-an-field/64296/5 "2016-10-28T15:20:05Z")

</div>

yes, seems like kibana don't allow aggregations: Discover: No query registered for [aggs]

Before came here I have tried on kibana forum but someone redirect me to elasticsearch forum. Probably I should rephrase my question. I hope now I have more clear difference between kibana queries and elasticsearch queries.

Thank you for help and have a nice weekend.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:08pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-by-an-field/64296/6 "2017-07-05T22:08:42Z")

</div>


