# Import aggregate data for each record

**URL:** <https://discuss.elastic.co/t/import-aggregate-data-for-each-record/120271>\
**Category:** Logstash\
**Created:** [February 16, 2018, 10:57pm UTC](https://discuss.elastic.co/t/import-aggregate-data-for-each-record/120271 "2018-02-16T22:57:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![akkash.bansal](https://avatars.discourse-cdn.com/v4/letter/a/ee7513/32.png) [@akkash.bansal](https://discuss.elastic.co/u/akkash.bansal)\
**Post date:** [February 16, 2018, 10:57pm UTC](https://discuss.elastic.co/t/import-aggregate-data-for-each-record/120271/1 "2018-02-16T22:57:40Z")

</div>

Hi,

I am trying to achieve following search record -  
{  
"hits": {  
"total": 148178,  
"max\_score": 1.0,  
"hits": [  
{  
"\_index": "ofc",  
"\_type": "pers\_desc",  
"\_id": "141234",  
"\_score": 1.0,  
"\_routing": "141234",  
"\_parent": "141234",  
"\_source": {  
"user\_id": "141234",  
"@version": "1",  
"@timestamp": "2018-01-09T18:42:11.301Z",  
"pdr": [  
{  
"gender": "MALE",  
"date\_of\_birth": "1965-04-20",  
"eye\_color": "BLUE",  
"hair\_color": "BLACK"  
}  
],  
"tags": [  
"aggregated"  
]  
}  
}  
]  
}  
}

And my aggregate filter config file is as below -  
input {  
jdbc {  
jdbc\_driver\_library =\> "C:\cfg\ojdbc6.jar"  
jdbc\_driver\_class =\> "Java::oracle.jdbc.driver.OracleDriver"  
jdbc\_connection\_string =\> "\<\<\>\>"  
jdbc\_user =\> "\<\<\>\>"  
jdbc\_password =\> "\<\<\>\>"  
statement\_filepath =\> "query.sql"  
}  
}

filter {  
aggregate {  
task\_id =\> "%{user\_id}"  
code =\>  
"  
map['pdr'] ||= [];  
map['pdr'] \<\< {  
'date\_of\_birth' =\> event.get('date\_of\_birth'),  
'eye\_color' =\> event.get('eye\_color'),  
'gender' =\> event.get('gender'),  
'hair\_color' =\> event.get('hair\_color')  
}  
event.cancel()  
"  
push\_previous\_map\_as\_event =\> true  
timeout =\> 3  
add\_tag =\> ["aggregate"]  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}

}

Pls. someone help me to achieve this. I am new to elastic search and log stash.

Thanks You.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2018, 10:57pm UTC](https://discuss.elastic.co/t/import-aggregate-data-for-each-record/120271/2 "2018-03-16T22:57:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
