# How to compute sum of field1 / sum of fileld2？

**URL:** <https://discuss.elastic.co/t/how-to-compute-sum-of-field1-sum-of-fileld2/107754>\
**Category:** Elasticsearch\
**Created:** [November 15, 2017, 1:30pm UTC](https://discuss.elastic.co/t/how-to-compute-sum-of-field1-sum-of-fileld2/107754 "2017-11-15T13:30:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![freebsdly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/freebsdly/32/24273_2.png) [@freebsdly](https://discuss.elastic.co/u/freebsdly)\
**Post date:** [November 15, 2017, 1:30pm UTC](https://discuss.elastic.co/t/how-to-compute-sum-of-field1-sum-of-fileld2/107754/1 "2017-11-15T13:30:09Z")

</div>

hi，all：  
i use elasticsearch2.4、logstash5.6.3 and grafana to monitoring network devices by netflow。but when i create dashboard in grafana to watch output port in someone device, i found sometimes the flow capacity large then the port's max physical capacity. the query dsl like this:

```auto
{
    "size": 0,
    "query": {
        "bool": {
            "filter": [{
                "range": {
                    "@timestamp": {
                        "gte": "1510749549284",
                        "lte": "1510751349284",
                        "format": "epoch_millis"
                    }
                }
            }, {
                "query_string": {
                    "analyze_wildcard": true,
                    "query": "host:(\"10.30.32.39\") AND netflow.input_snmp:(\"0\")"
                }
            }]
        }
    },
    "aggs": {
        "3": {
            "terms": {
                "field": "netflow.input_snmp",
                "size": 10,
                "order": {
                    "1": "desc"
                },
                "min_doc_count": 1
            },
            "aggs": {
                "1": {
                    "sum": {
                        "field": "netflow.bytes"
                    }
                },
                "2": {
                    "date_histogram": {
                        "interval": "10s",
                        "field": "@timestamp",
                        "min_doc_count": 0,
                        "extended_bounds": {
                            "min": "1510749549284",
                            "max": "1510751349284"
                        },
                        "format": "epoch_millis"
                    },
                    "aggs": {
                        "1": {
                            "sum": {
                                "field": "netflow.bytes"
                            }
                        }
                    }
                }
            }
        }
    }
}

```

i think the statistical method is wrong. so i modify logstash-codec-netflow source code :

- set field **netflow.last\_switched** and filed **netflow.first\_switched** type to **float** ;
- add a new field **netflow.duration = netflow.last\_switched - netflow.first\_switched** ;  
`event[@target]['duration'] = event[@target]['last_switched'] - event[@target]['first_switched']`
- set **@timestamp = netflow.last\_switched** ;  
`event[LogStash::Event::TIMESTAMP] = LogStash::Timestamp.at(seconds, micros).to_iso8601`
- add a new field **report** ;  
`"report" => LogStash::Timestamp.at(flowset.unix_sec.snapshot, flowset.unix_nsec.snapshot / 1000),`

now statistical method is **flow capacity = total netflow.bytes / total netflow.duration**.  
how to compute sum of netflow.bytes / sum of netflow.duration? use scripting ?

---

<div class="post-metadata">

**Author:** ![freebsdly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/freebsdly/32/24273_2.png) [@freebsdly](https://discuss.elastic.co/u/freebsdly)\
**Post date:** [November 15, 2017, 1:32pm UTC](https://discuss.elastic.co/t/how-to-compute-sum-of-field1-sum-of-fileld2/107754/2 "2017-11-15T13:32:14Z")

</div>

the netflow v5 : [http://netflow.caligare.com/netflow\_v5.htm](http://netflow.caligare.com/netflow_v5.htm)

---

<div class="post-metadata">

**Author:** ![costin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/costin/32/44950_2.png) [@costin](https://discuss.elastic.co/u/costin)\
**Post date:** [November 15, 2017, 4:20pm UTC](https://discuss.elastic.co/t/how-to-compute-sum-of-field1-sum-of-fileld2/107754/3 "2017-11-15T16:20:45Z")

</div>

Hi,

Scripting is designed for exactly the cases you mentioned - perform arbitrary computation on data coming from ES.  
See [this link](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-scripting.html) for more information.

---

<div class="post-metadata">

**Author:** ![freebsdly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/freebsdly/32/24273_2.png) [@freebsdly](https://discuss.elastic.co/u/freebsdly)\
**Post date:** [November 16, 2017, 2:36am UTC](https://discuss.elastic.co/t/how-to-compute-sum-of-field1-sum-of-fileld2/107754/4 "2017-11-16T02:36:28Z")

</div>

thank you. can i use inline script to implement ? because grafana only support in line script。

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2017, 2:36am UTC](https://discuss.elastic.co/t/how-to-compute-sum-of-field1-sum-of-fileld2/107754/5 "2017-12-14T02:36:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
