# How to aggregate multiple events coming from different logs with slight different timestamp, when the only field is timestamp to combine those?

**URL:** <https://discuss.elastic.co/t/how-to-aggregate-multiple-events-coming-from-different-logs-with-slight-different-timestamp-when-the-only-field-is-timestamp-to-combine-those/287848>\
**Category:** Logstash\
**Tags:** elastic-stack-machine-learning\
**Created:** [October 27, 2021, 7:19pm UTC](https://discuss.elastic.co/t/how-to-aggregate-multiple-events-coming-from-different-logs-with-slight-different-timestamp-when-the-only-field-is-timestamp-to-combine-those/287848 "2021-10-27T19:19:05Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [November 1, 2021, 6:46pm UTC](https://discuss.elastic.co/t/how-to-aggregate-multiple-events-coming-from-different-logs-with-slight-different-timestamp-when-the-only-field-is-timestamp-to-combine-those/287848/4 "2021-11-01T18:46:07Z")

</div>

First of all, metric analysis (using functions like `max`, `min`, `avg`, etc) can handle the data being sparse in a `bucket_span` and even sparse between `bucket_span`s. In other words, if you have a detector with `max(proecessing_time)` and a 5-minute `bucket_span`, but data comes every 10 minutes, it'll still work.

But, given your sample data, I have two major questions:

1. do you plan to split the data for each entity (something like `host.name`?)
2. Why do you feel compelled putting these all in the same ML job? Why not have several jobs, one for each data "type"?

---

_[View the full topic](https://discuss.elastic.co/t/how-to-aggregate-multiple-events-coming-from-different-logs-with-slight-different-timestamp-when-the-only-field-is-timestamp-to-combine-those/287848)._
