# Logstash aggregation to get total memory available at a timestamp

**URL:** <https://discuss.elastic.co/t/logstash-aggregation-to-get-total-memory-available-at-a-timestamp/268431>\
**Category:** Logstash\
**Created:** [March 26, 2021, 3:59am UTC](https://discuss.elastic.co/t/logstash-aggregation-to-get-total-memory-available-at-a-timestamp/268431 "2021-03-26T03:59:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![D\_R](https://avatars.discourse-cdn.com/v4/letter/d/ccd318/32.png) [@D\_R](https://discuss.elastic.co/u/D_R)\
**Post date:** [March 26, 2021, 3:59am UTC](https://discuss.elastic.co/t/logstash-aggregation-to-get-total-memory-available-at-a-timestamp/268431/1 "2021-03-26T03:59:23Z")

</div>

Hi,

I am new to logstash filters. My input files looks something like below  
'''  
{  
"@version" =\> "1",  
"collectd\_type" =\> "memory",  
"host" =\> "ubuntues",  
"type\_instance" =\> "slab\_unrecl",  
"plugin" =\> "memory",  
"value" =\> 29790208.0,  
"@timestamp" =\> 2021-03-26T03:49:56.814Z  
}  
{  
"@version" =\> "1",  
"collectd\_type" =\> "memory",  
"host" =\> "ubuntues",  
"type\_instance" =\> "slab\_recl",  
"plugin" =\> "memory",  
"value" =\> 69140480.0,  
"@timestamp" =\> 2021-03-26T03:49:56.814Z  
}  
{  
"@version" =\> "1",  
"collectd\_type" =\> "memory",  
"host" =\> "ubuntues",  
"type\_instance" =\> "free",  
"plugin" =\> "memory",  
"value" =\> 1964318720.0,  
"@timestamp" =\> 2021-03-26T03:50:06.782Z  
}  
{  
"@version" =\> "1",  
"collectd\_type" =\> "memory",  
"host" =\> "ubuntues",  
"type\_instance" =\> "slab\_unrecl",  
"plugin" =\> "memory",  
"value" =\> 29782016.0,  
"@timestamp" =\> 2021-03-26T03:50:06.782Z  
}  
{  
"@version" =\> "1",  
"collectd\_type" =\> "memory",  
"host" =\> "ubuntues",  
"type\_instance" =\> "slab\_recl",  
"plugin" =\> "memory",  
"value" =\> 69222400.0,  
"@timestamp" =\> 2021-03-26T03:50:06.782Z  
}  
{  
"@version" =\> "1",  
"collectd\_type" =\> "memory",  
"host" =\> "ubuntues",  
"type\_instance" =\> "used",  
"plugin" =\> "memory",  
"value" =\> 2545074176.0,  
"@timestamp" =\> 2021-03-26T03:50:06.782Z  
}  
{  
"@version" =\> "1",  
"collectd\_type" =\> "memory",  
"host" =\> "ubuntues",  
"type\_instance" =\> "buffered",  
"plugin" =\> "memory",  
"value" =\> 81203200.0,  
"@timestamp" =\> 2021-03-26T03:50:06.782Z  
}  
{  
"@version" =\> "1",  
"collectd\_type" =\> "memory",  
"host" =\> "ubuntues",  
"type\_instance" =\> "cached",  
"plugin" =\> "memory",  
"value" =\> 1032192000.0,  
"@timestamp" =\> 2021-03-26T03:50:06.782Z  
}  
'''  
I need to find a sum of all the values at same timestamp, so that I will get the total memory available at that time stamp. Your help will be much appreciated.

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [March 26, 2021, 5:23am UTC](https://discuss.elastic.co/t/logstash-aggregation-to-get-total-memory-available-at-a-timestamp/268431/2 "2021-03-26T05:23:50Z")

</div>

The aggregation has to be made in Elasticsearch.  
Logstash is more for parsing, enrichment and filtering.....

So what you need to do is collecting this events with e.g. an Logstash input and then send the events to Elasticsearch with the output.  
In Elasticsearch you can do these aggregation and many other things.

---

<div class="post-metadata">

**Author:** ![D\_R](https://avatars.discourse-cdn.com/v4/letter/d/ccd318/32.png) [@D\_R](https://discuss.elastic.co/u/D_R)\
**Post date:** [March 29, 2021, 4:26am UTC](https://discuss.elastic.co/t/logstash-aggregation-to-get-total-memory-available-at-a-timestamp/268431/3 "2021-03-29T04:26:50Z")

</div>

I am looking for some aggregation filter where it can be added as new field with logstash filter plugin

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2021, 4:27am UTC](https://discuss.elastic.co/t/logstash-aggregation-to-get-total-memory-available-at-a-timestamp/268431/4 "2021-04-26T04:27:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
