# Moving\_avg is throwing parse exception

**URL:** <https://discuss.elastic.co/t/moving-avg-is-throwing-parse-exception/37798>\
**Category:** Elasticsearch\
**Created:** [December 22, 2015, 10:07pm UTC](https://discuss.elastic.co/t/moving-avg-is-throwing-parse-exception/37798 "2015-12-22T22:07:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anirban\_mandal](https://avatars.discourse-cdn.com/v4/letter/a/ecccb3/32.png) [@Anirban\_mandal](https://discuss.elastic.co/u/Anirban_mandal)\
**Post date:** [December 22, 2015, 10:07pm UTC](https://discuss.elastic.co/t/moving-avg-is-throwing-parse-exception/37798/1 "2015-12-22T22:07:33Z")

</div>

New to ELK stack and facing some query issue.  
My index has the following metadata :  
{  
"data": {  
"properties": {  
"timestamp": {  
"format": "dateOptionalTime",  
"type": "date"  
},  
"qname": {  
"index": "not\_analyzed",  
"type": "string",  
"doc\_values": true  
},  
"outputproc": {  
"index": "not\_analyzed",  
"type": "integer",  
"doc\_values": true  
},  
"inputproc": {  
"index": "not\_analyzed",  
"type": "integer",  
"doc\_values": true  
},  
"depth": {  
"index": "not\_analyzed",  
"type": "integer",  
"doc\_values": true  
}  
}  
}  
}

And I am trying to query and aggregate it with qname and then depth every hour, I will have to do some percentile calculation later so I am doing the moving average and there its failing

Query :  
{  
"query": {  
"filtered": {  
"filter": {  
"range": {  
"data.timestamp": {  
"gte": "now-60d"  
}  
}  
}  
}  
},  
"size": "0",  
"aggs": {  
"metrics": {  
"terms": {  
"field": "data.depth"  
},  
"aggs": {  
"queries": {  
"terms": {  
"field": "data.qname"  
},  
"aggs": {  
"series": {  
"date\_histogram": {  
"field": "data.timestamp",  
"interval": "10m"  
},  
"aggs": {  
"this\_avg": {  
"avg": {  
"field": "data.depth"  
}  
},  
"movavg": {  
"moving\_avg": {  
"buckets\_path": "this\_avg",  
"window": "24",  
"model": "simple"  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}

Error : I am continuously getting a parse error like :  
"error": "SearchPhaseExecutionException[Failed  
to execute phase [query], all shards failed; shardFailures  
{[awrz\_ucVQiSSuLJLQ3-CvA][trialc\_mqstats][0]:  
RemoteTransportException[[Data\_3560\_data][inet[/10.1.117.39:9304]][indices:data/read/search[phase/query]]];  
nested: SearchParseException[[trialc\_mqstats][0]:  
query[ConstantScore(+cache(\_type:data)  
+no\_cache(timestamp:[1445637454220 TO \*]))],from[-1],size[0]: Parse  
Failure [Failed to parse source  
[{"query":{"filtered":{"filter":{"range":{"data.timestamp":{"gte":"now-60d"}}}}},"size":"0","aggs":{"metrics":{"terms":{"field":"data.depth"},"aggs":{"queries":{"terms":{"field":"data.qname"},"aggs":{"series":{"date\_histogram":{"field":"data.timestamp","interval":"10m"},"aggs":{"this\_avg":{"avg":{"field":"data.depth"}},"movavg":{"moving\_avg":{"buckets\_path":"this\_avg","window":"24","model":"simple"}}}}}}}}}}]]];  
nested: SearchParseException[[trialc\_mqstats][0]:  
query[ConstantScore(+cache(\_type:data)  
+no\_cache(timestamp:[1445637454220 TO \*]))],from[-1],size[0]: Parse  
Failure [Could not find aggregator type [moving\_avg] in [movavg]]];

can some one please point out my mistake here. I think its a syntax issue  
ES version : 2.1.0

---

<div class="post-metadata">

**Author:** ![Anirban\_mandal](https://avatars.discourse-cdn.com/v4/letter/a/ecccb3/32.png) [@Anirban\_mandal](https://discuss.elastic.co/u/Anirban_mandal)\
**Post date:** [December 23, 2015, 2:50pm UTC](https://discuss.elastic.co/t/moving-avg-is-throwing-parse-exception/37798/2 "2015-12-23T14:50:50Z")

</div>

Apologies -- my ES version was old, I upgraded to 2.1.0 and now its supporting. We can close this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:29pm UTC](https://discuss.elastic.co/t/moving-avg-is-throwing-parse-exception/37798/3 "2017-07-05T23:29:03Z")

</div>


