# Logstash aggregate and calculate the sum of counts

**URL:** <https://discuss.elastic.co/t/logstash-aggregate-and-calculate-the-sum-of-counts/334495>\
**Category:** Logstash\
**Created:** [May 27, 2023, 10:20am UTC](https://discuss.elastic.co/t/logstash-aggregate-and-calculate-the-sum-of-counts/334495 "2023-05-27T10:20:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![m3bgwad](https://avatars.discourse-cdn.com/v4/letter/m/a183cd/32.png) [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Post date:** [May 27, 2023, 10:20am UTC](https://discuss.elastic.co/t/logstash-aggregate-and-calculate-the-sum-of-counts/334495/1 "2023-05-27T10:20:07Z")

</div>

Hello All,  
I have a scenario, I need the expertise to support this, and thanks in advanced

```auto
I have a statement running by the JDBC input plugin every 1 minute, so the results returned every 1 minute until if the results are NULL I did assigned a default value like zero to control that every 1 minute there is data,
so this statement returned different types and counts, if I want to track these counts based on each result or If the last 10 minutes the sum of counts = 0 this moment I know there is no data,

```

```auto
input {
  jdbc {
    jdbc_driver_library => ""
    jdbc_driver_class => ""
    jdbc_connection_string => "" 
    jdbc_user => ""
    jdbc_password => ""
    schedule => "* * * * *"
    statement => "select type, count from mytable
filter {
  if "type1" in [itype] {
     aggregate {
       task_id => "%{type1}"
       code => "map['count'] ||= 0; map['count'] += event.get('totalcount')"
       push_map_as_event_on_timeout => true
       timeout_task_id_field => "invoice type"
       timeout => 600
       timeout_code => "event.set('sumcount', event.get('totalcoun'))" }
 }
}
output {
  elasticsearch {}
}

```

1- I want to calculate the sum count of the last 10 or 60 minutes whatever  
2- if the count of last 10 events of last 10 minutes equal 0 take action else take another action like (add count = 0),  
thanks,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2023, 10:20am UTC](https://discuss.elastic.co/t/logstash-aggregate-and-calculate-the-sum-of-counts/334495/2 "2023-06-24T10:20:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
