# Perform aggregation on the result of a subquery aggregation

**URL:** <https://discuss.elastic.co/t/perform-aggregation-on-the-result-of-a-subquery-aggregation/19815>\
**Category:** Elasticsearch\
**Created:** [September 16, 2014, 1:55pm UTC](https://discuss.elastic.co/t/perform-aggregation-on-the-result-of-a-subquery-aggregation/19815 "2014-09-16T13:55:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guillaume1](https://avatars.discourse-cdn.com/v4/letter/g/c5a1d2/32.png) [@Guillaume1](https://discuss.elastic.co/u/Guillaume1)\
**Post date:** [September 16, 2014, 1:55pm UTC](https://discuss.elastic.co/t/perform-aggregation-on-the-result-of-a-subquery-aggregation/19815/1 "2014-09-16T13:55:43Z")

</div>

Hi,

I'm newbie with Elastic search. I'm validating Elasticsearch regarding our  
needs.

Lets say I want to monitor disk usage of my VMs.

- vm1 and vm2 are in Platform PF\_A, vm3 is in platform PF\_B

The mapping I declared (can be pasted in sense)  
PUT /example\_201408/vm/\_mapping  
{  
"\_timestamp" : {  
"enabled" : true,  
"default" : null  
},  
"properties": {  
"date": {  
"type": "date"  
},  
"platform": {  
"type": "string"  
},  
"disk-used": {  
"type": "float"  
}  
}  
}

once a day, I collect the disk usage for all my vms and I store data in  
E.S:  
POST /example\_201408/vm/vm1\_20140825  
{  
"\_timestamp": "2014-08-25T14:02:12.000Z",  
"ip": "192.168.0.1",  
"platform" : "pf\_A",  
"disk-used": 10  
}  
POST /example\_201408/vm/vm2\_20140825  
{  
"\_timestamp": "2014-08-25T14:02:12.000Z",  
"ip": "192.168.0.2",  
"platform" : "pf\_A",  
"disk-used": 30  
}  
POST /example\_201408/vm/vm3\_20140825  
{  
"\_timestamp": "2014-08-25T14:02:12.000Z",  
"ip": "192.168.0.3",  
"platform" : "pf\_B",  
"disk-used": 40  
}

POST /example\_201408/vm/vm1\_20140826  
{  
"\_timestamp": "2014-08-26T14:02:12.000Z",  
"ip": "192.168.0.1",  
"platform" : "pf\_A",  
"disk-used": 15  
}

I would like to have

- \*I successfully lookup data per ip, grouped by platform (in  
buckets) at specified date (now) \*using this query

GET /example\_201408/\_search?search\_type=count&pretty=true  
{  
"aggs": {  
"current\_pf\_statuses": {  
"terms": {  
"field": "platform"  
},  
"aggs": {  
"current\_ip\_statuses": {  
"terms": {  
"field": "ip"  
},  
"aggs": {  
"current\_status\_per\_pf": {  
"top\_hits": {  
"sort": [  
{  
"\_timestamp": {  
"order": "desc"  
}  
}  
],  
"size": 1  
}  
}  
}  
}  
}  
}  
}  
}

\*I don't know how to sum disk-usage per Platform at specified date. \*

I would imagine to use the result of the first query in another one that  
would aggregate over the platform field but I don't know how to do?

Is it possible to aggregate data per buckets ?

Regards,  
Guillaume

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/8096f21c-a0ac-4b07-af5d-0ab36f1f43aa%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/8096f21c-a0ac-4b07-af5d-0ab36f1f43aa%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:01am UTC](https://discuss.elastic.co/t/perform-aggregation-on-the-result-of-a-subquery-aggregation/19815/2 "2017-07-06T01:01:59Z")

</div>


