# Is it possible to add a field to all document in an index which the field is an aggregation result?

**URL:** <https://discuss.elastic.co/t/is-it-possible-to-add-a-field-to-all-document-in-an-index-which-the-field-is-an-aggregation-result/197109>\
**Category:** Elasticsearch\
**Created:** [August 28, 2019, 12:09pm UTC](https://discuss.elastic.co/t/is-it-possible-to-add-a-field-to-all-document-in-an-index-which-the-field-is-an-aggregation-result/197109 "2019-08-28T12:09:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mmk1995](https://avatars.discourse-cdn.com/v4/letter/m/8797f3/32.png) [@mmk1995](https://discuss.elastic.co/u/mmk1995)\
**Post date:** [August 28, 2019, 12:09pm UTC](https://discuss.elastic.co/t/is-it-possible-to-add-a-field-to-all-document-in-an-index-which-the-field-is-an-aggregation-result/197109/1 "2019-08-28T12:09:32Z")

</div>

Hello all,

I have data set as below:

```
on_time,off_time,user,PC
2018-09-01 00:34:27.540,2018-09-01 03:40:34.870,wwwww,NA016F
2018-09-01 02:55:55.710,2018-09-01 02:58:55.860,dddddd,NB106F
2018-09-01 03:44:24.460,2018-09-01 04:18:32.300,eeeeeee,NA031F
2018-09-01 04:45:26.150,2018-09-01 05:55:53.580,gggggggg,NA046F
2018-09-01 06:18:43.460,2018-09-01 10:02:28.490,bbbbbbb,CC004D
2018-09-01 08:06:22.880,2018-09-01 13:54:01.040,fffffffffff,NB083F
2018-09-01 08:07:24.530,2018-09-01 08:12:20.880,gggggggg,NA091F
2018-09-01 08:14:11.630,2018-09-01 08:17:43.300,mmmmm,NA110F

```

I want to add a field called "time\_frame" which is the date range between "on\_time" and "off\_time" to all documents in a index, what is the Elasticsearch command to perform this?

thank you very much.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 28, 2019, 2:26pm UTC](https://discuss.elastic.co/t/is-it-possible-to-add-a-field-to-all-document-in-an-index-which-the-field-is-an-aggregation-result/197109/2 "2019-08-28T14:26:03Z")

</div>

Hey,

so if the documents have already been indexed, you could use the [update by query API](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/docs-update-by-query.html) and execute a script that calculates the duration between the two timestamps.

--Alex

---

<div class="post-metadata">

**Author:** ![mmk1995](https://avatars.discourse-cdn.com/v4/letter/m/8797f3/32.png) [@mmk1995](https://discuss.elastic.co/u/mmk1995)\
**Post date:** [August 29, 2019, 3:32am UTC](https://discuss.elastic.co/t/is-it-possible-to-add-a-field-to-all-document-in-an-index-which-the-field-is-an-aggregation-result/197109/3 "2019-08-29T03:32:44Z")

</div>

hello Alex,  
I hope there will be a good code example like my case,  
I have read your link but I really not understanding well from the examples  
and nonetheless the examples are too simple and I cannot really take them as reference  
also painless script example are also too little  
if possible, I hope you could show some coding for my case  
Thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 29, 2019, 7:29am UTC](https://discuss.elastic.co/t/is-it-possible-to-add-a-field-to-all-document-in-an-index-which-the-field-is-an-aggregation-result/197109/4 "2019-08-29T07:29:24Z")

</div>

See [Unable to calculate duration by 2 dates fields](https://discuss.elastic.co/t/unable-to-calculate-duration-by-2-dates-fields/194833/3) for some inspiration

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2019, 7:30am UTC](https://discuss.elastic.co/t/is-it-possible-to-add-a-field-to-all-document-in-an-index-which-the-field-is-an-aggregation-result/197109/5 "2019-09-26T07:30:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
