Perform aggregation on already aggregated result

(Clindo) #1


I am performing an aggregation of Netflow records. My first aggregation is to collect all documents within a "100ms" interval. Now I want to do an aggregation on a particular field in this interval, say protocol used during this interval. So, how could I structure a query so that, I can get the total number of docs in each interval along with the count of docs having the particular protocol?

(system) #2

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.