# Logstash - Elastic search input plugin - Aggregation query doesn't seem to work

**URL:** https://discuss.elastic.co/t/logstash-elastic-search-input-plugin-aggregation-query-doesnt-seem-to-work/171147
**Category:** Logstash
**Created:** [March 6, 2019, 4:01pm UTC](https://discuss.elastic.co/t/logstash-elastic-search-input-plugin-aggregation-query-doesnt-seem-to-work/171147 "2019-03-06T16:01:04Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Kyle\_Ryan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kyle_ryan/32/42484_2.png) [@Kyle\_Ryan](https://discuss.elastic.co/u/Kyle_Ryan)
#### Post date: [March 25, 2019, 8:26pm UTC](https://discuss.elastic.co/t/logstash-elastic-search-input-plugin-aggregation-query-doesnt-seem-to-work/171147/2 "2019-03-25T20:26:35Z")

</div>

I have the same issue. It seems to be related the behavior of the scroll api with respect to aggregations.  
It would appear from the docs that this plugin uses a scroll query, which does not play nice with aggregations. In 2.3 and earlier you could choose whether you wanted the query to be executed as an ordinary query, or as a scan and scroll via the "scan" parameter.

> **[elasticsearch | Logstash Reference \[2.3\] | Elastic](https://www.elastic.co/guide/en/logstash/2.3/plugins-inputs-elasticsearch.html#plugins-inputs-elasticsearch-scan)**

But support for that was dropped in 2.4.

It is worth noting that this question has been asked many times before.  
2017:

> [@ES Aggregation as Logstash Input](https://discuss.elastic.co/t/es-aggregation-as-logstash-input/106927):
>
> I found 2 topics on this topic with no clear solution. I eventually got it working. [How to get ES aggregation data as Logstash input?](https://discuss.elastic.co/t/how-to-get-es-aggregation-data-as-logstash-input/64776)[Aggregation Query possible input ES plugin](https://discuss.elastic.co/t/aggregation-query-possible-input-es-plugin/28159) I basically used the curl to output ES aggregate query to file and then used file input to read and convert to csv. But same can be done to send aggregate data to ES as a new index. input { pipe { codec =\> "json" command =\> "./ord\_summary\_curl.sh" } } filter { split { field =\> "[aggregations][by-dat…

2016:

> [@How to get ES aggregation data as Logstash input?](https://discuss.elastic.co/t/how-to-get-es-aggregation-data-as-logstash-input/64776):
>
> I have a Logstash configuration with the 'elasticsearch' input. input { elasticsearch { hosts =\> "localhost" index =\> "logstash-\*" type =\> 'aggregation\_metric' size =\> 0 query =\> ' { "size": 0, "aggs": { ... here is multi-level aggregation without buckets } }' I'm trying to send [aggregation result](https://discuss.elastic.co/t/how-to-get-dau-wau-charts-in-elasticsearch/64774) as a new document in new index of ES. I don't need any documents from the root level of searching, but maybe some of documents fro…

2015:

> [@Aggregation Query possible input ES plugin](https://discuss.elastic.co/t/aggregation-query-possible-input-es-plugin/28159):
>
> I really want to know that aggregation is possible in input / output plugin ? input { Read all documents from Elasticsearch matching the given query elasticsearch { hosts =\> ["192.168.1.5"] index =\> "matching\_score\_log" type =\> "keyword\_score" port =\> 9200 size =\> 0 docinfo =\> true scan =\> false query =\> '{"aggs":{"terms\_keyword":{"terms":{"field":"user\_keyword","size":0},"aggs":{"key\_score":{"terms":{"field":"inquiry\_id","size":0},"aggs":{"key\_score":{"sum":{"field":"inquiry\_score"…

There's even an open issue for it.

> <https://github.com/logstash-plugins/logstash-input-elasticsearch/issues/58>
>
> Not sure if this would be better supported by a totally different plugin, but I …think it would make sense to support aggregation results.  
> 
> As an example, say we wanted to use a sum aggregation, by terms.
> 
> \`\`\`
> GET myserverlogs\*/\_search
> {
> 
> "size": 0,
> "aggs": {
> "types": {
> "terms": {
> "field": "hostname"
> },
> "aggs": {
> "connections": {
> "sum": {
> "field": "connections"
> }
> }
> }
> }
> }
> }
> \`\`\`
> 
> Results:
> \`\`\`
> "aggregations": {
> "types": {
> "doc\_count\_error\_upper\_bound": 0,
> "sum\_other\_doc\_count": 0,
> "buckets": \[
> {
> "key": "hostA",
> "doc\_count": 90310,
> "total\_connections": {
> "value": 2344
> }
> },
> {
> "key": "hostB",
> "doc\_count": 485,
> "total\_connections": {
> "value": 233
> }
> },
> {
> "key": "hostC",
> "doc\_count": 485,
> "total\_connections": {
> "value": 123
> }
> }
> \]
> }
> }
> \`\`\`
> 
> Then in Logstash we could say something like:
> 
> \`\`\`
> input {
> elasticsearch {
> ...
> results\_mode =\> "aggregation"
> source\_array =\> "types.buckets"
> }
> }
> \`\`\`
> 
> This could even be used to create aggregation based summary indices on a regular interval. I remember @polyfractal was working on an ES plugin that did something similar last year.

For now your best bet is probably to use one of the workarounds suggested with bash/php in previous questions. Or you could try and write up a PR to address the issue.

Not sure if anyone else has news on support for elastic aggregations within the elastic input plugin, it's a sorely needed feature to be sure.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-elastic-search-input-plugin-aggregation-query-doesnt-seem-to-work/171147)._
