# Merging results of similar aggregation buckets to perform union and intersect

**URL:** <https://discuss.elastic.co/t/merging-results-of-similar-aggregation-buckets-to-perform-union-and-intersect/155099>\
**Category:** Logstash\
**Created:** [November 2, 2018, 1:41am UTC](https://discuss.elastic.co/t/merging-results-of-similar-aggregation-buckets-to-perform-union-and-intersect/155099 "2018-11-02T01:41:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dx123](https://avatars.discourse-cdn.com/v4/letter/d/d9b06d/32.png) [@dx123](https://discuss.elastic.co/u/dx123)\
**Post date:** [November 2, 2018, 1:41am UTC](https://discuss.elastic.co/t/merging-results-of-similar-aggregation-buckets-to-perform-union-and-intersect/155099/1 "2018-11-02T01:41:35Z")

</div>

Here is an example of the aggregation bucket results that I have now:  
"aggregations":{  
"by ip":{  
"buckets":[  
{  
"key":"192.168.0.1",  
"doc\_count":2,  
"by date":{  
"buckets":[  
{  
"key\_as\_string":"2018-01-01T00:00:00.000Z",  
"key":1111000000000,  
"doc\_count":1,  
"by ports":{  
"buckets":[  
{  
"key":"TCP1",  
"doc\_count":1  
},  
{  
"key":"TCP2",  
"doc\_count":1  
}  
]  
}  
},  
{  
"key\_as\_string":"2018-01-02T00:00:00.000Z",  
"key":1000000000000,  
"doc\_count":1,  
"by ports":{  
"buckets":[  
{  
"key":"TCP2",  
"doc\_count":1  
},  
{  
"key":"UDP1",  
"doc\_count":1  
}  
]  
}  
]  
}  
}

How do I merge the results of the 2 bucket days together to get calculations such as the union and intersect of the ports that I can set to new aggregation buckets?

Union: TCP1, TCP2, UDP1  
Intersect: TCP2

It seems that the default bucket and pipeline aggregation features are unable to perform this. Would a painless/python bucket script aggregation work and are there any other alternative methods?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2018, 1:41am UTC](https://discuss.elastic.co/t/merging-results-of-similar-aggregation-buckets-to-perform-union-and-intersect/155099/2 "2018-11-30T01:41:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
