# Pipeline aggregation: date histogram + terms

**URL:** <https://discuss.elastic.co/t/pipeline-aggregation-date-histogram-terms/68067>\
**Category:** Elasticsearch\
**Created:** [December 5, 2016, 4:10pm UTC](https://discuss.elastic.co/t/pipeline-aggregation-date-histogram-terms/68067 "2016-12-05T16:10:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![arno-london](https://avatars.discourse-cdn.com/v4/letter/a/898d66/32.png) [@arno-london](https://discuss.elastic.co/u/arno-london)\
**Post date:** [December 5, 2016, 4:10pm UTC](https://discuss.elastic.co/t/pipeline-aggregation-date-histogram-terms/68067/1 "2016-12-05T16:10:21Z")

</div>

Hi,

I would like to dynamically build fixed size buckets over the dates (date\_histogram). Then, for every date range, I would like buckets dynamically built one per term. So the result would be something like that:

```
[
  {
    "timestamp": "month0",
    "tags": [
       "blue": 41,
       "red": 35,
       "green": 21
    ]
  },
  ...
  {
    "timestamp": "monthN",
    "tags": [
       "blue": 41,
       "red": 35,
       "green": 21
    ]
  },
]

```

In order to achieve that I did the following pipeline aggregation, but it doesn't work:

```
{
    "aggs" : {
        "sales_per_month" : {
            "date_histogram" : {
                "field" : "date",
                "interval" : "month"
            },
            "aggs": {
                "tags": {
                    "terms": {
                        "field": "tags"
                    }
                }
            }
        },
        "monthly_tags": {
            "bucket": {
                "buckets_path": "sales_per_month>tags" 
            }
        }
    }
}

```

Any tips?  
Thanks

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [December 6, 2016, 12:48pm UTC](https://discuss.elastic.co/t/pipeline-aggregation-date-histogram-terms/68067/2 "2016-12-06T12:48:05Z")

</div>

Hi @arno-london,

isn't this doing what you want?

```auto
DELETE /test

PUT /test
{
    "mappings": {
        "type": {
            "properties": {
                "timestamp": {
                    "type": "date"
                },
                "tags": {
                    "type": "keyword"
                }
            }
        }
    }
}

POST /test/type/_bulk
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-01-01", "tags": ["red", "green"]}
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-01-01",	"tags": ["blue"]}
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-01-01",	"tags": ["blue"]}
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-01-01",	"tags": ["blue"]}
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-01-01",	"tags": ["green"]}
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-02-01",	"tags": ["green"]}
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-02-01",	"tags": ["green"]}
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-02-01",	"tags": ["green"]}
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-02-01",	"tags": ["green"]}
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-02-01",	"tags": ["red"]}
{ "index": {"_index": "test", "_type": "type"} }
{"timestamp": "2016-03-01",	"tags": ["blue"]}

GET /test/type/_search
{
    "query": {
        "match_all": {}
    }, 
    "size": 0, 
    "aggs" : {
        "sales_per_month" : {
            "date_histogram" : {
                "field" : "timestamp",
                "interval" : "month"
            },
            "aggs": {
                "tags": {
                    "terms": {
                        "field": "tags"
                    }
                }
            }
        }
    }
}

```

This produces:

```auto
{
   "took": 2,
   "timed_out": false,
   "_shards": {
      "total": 5,
      "successful": 5,
      "failed": 0
   },
   "hits": {
      "total": 11,
      "max_score": 0,
      "hits": []
   },
   "aggregations": {
      "sales_per_month": {
         "buckets": [
            {
               "key_as_string": "2016-01-01T00:00:00.000Z",
               "key": 1451606400000,
               "doc_count": 5,
               "tags": {
                  "doc_count_error_upper_bound": 0,
                  "sum_other_doc_count": 0,
                  "buckets": [
                     {
                        "key": "blue",
                        "doc_count": 3
                     },
                     {
                        "key": "green",
                        "doc_count": 2
                     },
                     {
                        "key": "red",
                        "doc_count": 1
                     }
                  ]
               }
            },
            {
               "key_as_string": "2016-02-01T00:00:00.000Z",
               "key": 1454284800000,
               "doc_count": 5,
               "tags": {
                  "doc_count_error_upper_bound": 0,
                  "sum_other_doc_count": 0,
                  "buckets": [
                     {
                        "key": "green",
                        "doc_count": 4
                     },
                     {
                        "key": "red",
                        "doc_count": 1
                     }
                  ]
               }
            },
            {
               "key_as_string": "2016-03-01T00:00:00.000Z",
               "key": 1456790400000,
               "doc_count": 1,
               "tags": {
                  "doc_count_error_upper_bound": 0,
                  "sum_other_doc_count": 0,
                  "buckets": [
                     {
                        "key": "blue",
                        "doc_count": 1
                     }
                  ]
               }
            }
         ]
      }
   }
}

```

Daniel

---

<div class="post-metadata">

**Author:** ![arno-london](https://avatars.discourse-cdn.com/v4/letter/a/898d66/32.png) [@arno-london](https://discuss.elastic.co/u/arno-london)\
**Post date:** [December 6, 2016, 1:04pm UTC](https://discuss.elastic.co/t/pipeline-aggregation-date-histogram-terms/68067/3 "2016-12-06T13:04:12Z")

</div>

Yes! **Many thanks!**

There is something I didn't understand with the pipeline aggregation, I have to read the documentation again.

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [December 6, 2016, 1:13pm UTC](https://discuss.elastic.co/t/pipeline-aggregation-date-histogram-terms/68067/4 "2016-12-06T13:13:29Z")

</div>

Hi @arno-london,

great that I could help you! 🙂

Daniel

---

<div class="post-metadata">

**Author:** ![arno-london](https://avatars.discourse-cdn.com/v4/letter/a/898d66/32.png) [@arno-london](https://discuss.elastic.co/u/arno-london)\
**Post date:** [December 6, 2016, 1:26pm UTC](https://discuss.elastic.co/t/pipeline-aggregation-date-histogram-terms/68067/5 "2016-12-06T13:26:38Z")

</div>

A big help!  
Have a great day Daniel!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2017, 1:26pm UTC](https://discuss.elastic.co/t/pipeline-aggregation-date-histogram-terms/68067/6 "2017-01-03T13:26:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
