# Post-processing aggregations data

**URL:** <https://discuss.elastic.co/t/post-processing-aggregations-data/1261>\
**Category:** Elasticsearch\
**Created:** [May 25, 2015, 5:56pm UTC](https://discuss.elastic.co/t/post-processing-aggregations-data/1261 "2015-05-25T17:56:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![haizaar](https://avatars.discourse-cdn.com/v4/letter/h/3d9bf3/32.png) [@haizaar](https://discuss.elastic.co/u/haizaar)\
**Post date:** [May 25, 2015, 5:56pm UTC](https://discuss.elastic.co/t/post-processing-aggregations-data/1261/1 "2015-05-25T17:56:06Z")

</div>

Good day,

I have a (simplified) mapping that stores throughput metrics every second:

```
{ "sample": {
        "properties": {
            "timestamp": { "type": "date" },
            "throughput": { "type": "long" }
        }
} }

```

I would like to calculate average throughput in megabytes per second over 1-minute buckets.

So far I found two ways of doing this:

**1. Sum aggregation with post-processing:**

```
{ "aggs": {
    "date_agg": {
      "date_range": {
        "field": "timestamp",
        "ranges": [
          { "from": "2015-05-25T14:50:00.000Z", "to": "2015-05-25T14:51:00.000Z" }
          .... <several hundred more buckets>
        ]
      },
      "aggs": {
        "total_throughput": {
          "sum": { "field": "timestamp" }
} } } } }

```

And then divide value of each bucket to (60_1024_1024) on the client side after fetching the data from ES.

**2. With a scripted metric:**

```
{ "aggs": {
    "date_agg": {
      "date_range": {
        "field": "timestamp",
        "ranges": [
          { "from": "2015-05-25T14:50:00.000Z", "to": "2015-05-25T14:51:00.000Z" }
          .... <several hundred more buckets>
        ]
      },
      "aggs": {
        "thoughput_per_sec": {
          "scripted_metric": {
            "init_script": "_agg['tp'] = 0",
            "map_script": "_agg.tp += doc['throughput'].value",
            "reduce_script": "tps = 0; for (a in _aggs) { tps += a['tp'] }; return Math.round(tps/60/1024/1024 * 100)/100"
} } } } } }

```

The scripted metric works great, except that it's about 4 times slower then doing just `sum` and then division on the client side.

I wondering if there is a way to define a script that runs on results of the aggregation. This way I can still use fast built-in `sum` agg then do the final calculations in the script (which will run only on several hundreds buckets, to its no biggie).

P.S. No, I can't just use `avg`, because I have slightly more complex things to calculate that obviously have no built-in aggregation I can use.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:12am UTC](https://discuss.elastic.co/t/post-processing-aggregations-data/1261/2 "2017-07-06T00:12:04Z")

</div>


