# How to Sum two or more integer from different logs

**URL:** <https://discuss.elastic.co/t/how-to-sum-two-or-more-integer-from-different-logs/269767>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-sql, painless\
**Created:** [April 10, 2021, 9:32am UTC](https://discuss.elastic.co/t/how-to-sum-two-or-more-integer-from-different-logs/269767 "2021-04-10T09:32:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Farid\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farid_n/32/74144_2.png) [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Post date:** [April 10, 2021, 9:32am UTC](https://discuss.elastic.co/t/how-to-sum-two-or-more-integer-from-different-logs/269767/1 "2021-04-10T09:32:29Z")

</div>

Hi  
I have 2logs:

```auto
{
  "_index": "monitoring",
  "_type": "_doc",
  "_id": "1",
  "_version": 1,
  "_score": null,
  "_source": {
    "jobtypedescription": "Monitor",
    "@version": "1",
    "jobtypeid": 1,
    "jobactionid": 100030,
    "@timestamp": "2021-04-10T02:30:00.564Z",
    "Count": 1308,
    "ApplicationName": "ExtendSubscription",
    "actiondescription": "Zabbix"
  }

```

The other one is:

```auto
{
  "_index": "monitoring",
  "_type": "_doc",
  "_id": "2",
  "_version": 1,
  "_score": null,
  "_source": {
    "jobtypedescription": "Monitor",
    "@version": "1",
    "jobtypeid": 1,
    "jobactionid": 100030,
    "@timestamp": "2021-04-10T02:30:00.564Z",
    "Count": 6131,
    "ApplicationName": "ExtendSubscription",
    "actiondescription": "Zabbix"
  }

```

As you see there is an integer filed name `Count` in both logs (1308 & 6131). I need a query to return the SUM of this `Count`. For instance I want `"total" : 7439`

What will the query look like?

Thanks in advanced

---

<div class="post-metadata">

**Author:** ![Farid\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farid_n/32/74144_2.png) [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Post date:** [April 10, 2021, 9:37am UTC](https://discuss.elastic.co/t/how-to-sum-two-or-more-integer-from-different-logs/269767/2 "2021-04-10T09:37:03Z")

</div>

I searched the link bellow:

> **[Sum aggregation | Elasticsearch Guide \[7.12\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-sum-aggregation.html)**

Is this correct?

---

<div class="post-metadata">

**Author:** ![Farid\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farid_n/32/74144_2.png) [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Post date:** [April 10, 2021, 11:21am UTC](https://discuss.elastic.co/t/how-to-sum-two-or-more-integer-from-different-logs/269767/3 "2021-04-10T11:21:09Z")

</div>

This query works:

```auto
GET /job-*/_search
{
  "query": {
    "constant_score": {
      "filter": {
        "match":{"jobtypeid":"1"}
      }
    }
  },
  "aggs": {
    "total_Count": {"sum": {
      "field": "Count"
    }
    }
  }
}

```

But it has a problem, I just want to aggerate only last 24hours... So I try this:

```auto
GET /job-*/_search
{
  "query": {
    "constant_score": {
      "filter": {
        "match":{"jobtypeid":"1"}
      }
    },
    "range": {
      "@timestamp": {
        "gte": "now-24h",
        "lte": "now"
      }
    }
  },
  "aggs": {
    "total_Count": {"sum": {
      "field": "Count"
    }
    }
  }
}

```

But I faced with this error:

```auto
  "error" : {
    "root_cause" : [
      {
        "type" : "parsing_exception",
        "reason" : "[constant_score] malformed query, expected [END_OBJECT] but found [FIELD_NAME]",
        "line" : 8,
        "col" : 5
      }
    ],
    "type" : "parsing_exception",
    "reason" : "[constant_score] malformed query, expected [END_OBJECT] but found [FIELD_NAME]",
    "line" : 8,
    "col" : 5
  },
  "status" : 400
}

```

Why I can not use this range API ?!? I used this `range` before (for other queries)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 10, 2021, 11:27am UTC](https://discuss.elastic.co/t/how-to-sum-two-or-more-integer-from-different-logs/269767/4 "2021-04-10T11:27:13Z")

</div>

You need to put both queries (`match` and `range`) in a `bool` query instead.

---

<div class="post-metadata">

**Author:** ![Farid\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farid_n/32/74144_2.png) [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Post date:** [April 10, 2021, 11:56am UTC](https://discuss.elastic.co/t/how-to-sum-two-or-more-integer-from-different-logs/269767/5 "2021-04-10T11:56:11Z")

</div>

Oh I forgot...  
Thank you so much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2021, 11:56am UTC](https://discuss.elastic.co/t/how-to-sum-two-or-more-integer-from-different-logs/269767/6 "2021-05-08T11:56:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
