# Is it possible to create a dynamic, rolling interval within a date\_histogram?

**URL:** <https://discuss.elastic.co/t/is-it-possible-to-create-a-dynamic-rolling-interval-within-a-date-histogram/78040>\
**Category:** Elasticsearch\
**Created:** [March 9, 2017, 7:09pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-dynamic-rolling-interval-within-a-date-histogram/78040 "2017-03-09T19:09:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![t.Farestad](https://avatars.discourse-cdn.com/v4/letter/t/3ab097/32.png) [@t.Farestad](https://discuss.elastic.co/u/t.Farestad)\
**Post date:** [March 9, 2017, 7:09pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-dynamic-rolling-interval-within-a-date-histogram/78040/1 "2017-03-09T19:09:07Z")

</div>

One of our current monitors, uses a date\_histogram to break the last two days worth of data into buckets in hour intervals:

"aggs": {  
"histo": {  
"date\_histogram": {  
"field": "@timestamp",  
"interval": "1h"  
},

I think do a bucket\_script on each of these intervals, and compute success rate. I can then do an extended stats bucket to generate the average/std deviation across these buckets to generate a baseline to compare my last bucket to.

The issue I'm having is in the way that ElasticSearch breaks down the intervals. Doing a 1 hour interval doesn't break the buckets into the last 60 minutes, instead, it is based off the buckets generated forward using the interval starting at like 1/1/1970 or something like that. What happens then is, when my alert runs at 1:05 pm, the last "last bucket" really only contains 5 minutes worth of data, which means I'm comparing a much lower volume, where 1 error has a drastic impact on the success rate.

Is there anyway to create dynamic rolling time intervals that are truly the last 60 minutes?

I know you can use offset, but I would need an offset that changes depending on when the script is ran.

I would need something like "offset" : "now - (60 - (now().min))". (Just made up that syntax, but I'm sure you get my point, where now().min returns the minutes past the current hour. So that at 1:05, the offset moves back 55 minutes, and the the last "hour" bucket is actually from 12:05 -\> 1:05 giving a true hour's worth of data.

Is this possible with an inline script? Can I use a script to create a parameter/variable and shove that into offset dynamically?

---

<div class="post-metadata">

**Author:** ![t.Farestad](https://avatars.discourse-cdn.com/v4/letter/t/3ab097/32.png) [@t.Farestad](https://discuss.elastic.co/u/t.Farestad)\
**Post date:** [March 13, 2017, 2:14pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-dynamic-rolling-interval-within-a-date-histogram/78040/2 "2017-03-13T14:14:48Z")

</div>

Still havn't figured this one out. Anyone able to do something similar?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 13, 2017, 9:11pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-dynamic-rolling-interval-within-a-date-histogram/78040/3 "2017-03-13T21:11:52Z")

</div>

Hey,

would the [offset parameter](https://www.elastic.co/guide/en/elasticsearch/reference/5.2/search-aggregations-bucket-datehistogram-aggregation.html#_offset) in the date histogram aggregation work for you?

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2017, 9:12pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-dynamic-rolling-interval-within-a-date-histogram/78040/4 "2017-04-10T21:12:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
