# Question for Aggregation

**URL:** <https://discuss.elastic.co/t/question-for-aggregation/46936>\
**Category:** Elasticsearch\
**Created:** [April 11, 2016, 4:04am UTC](https://discuss.elastic.co/t/question-for-aggregation/46936 "2016-04-11T04:04:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ori.rubinfeld](https://avatars.discourse-cdn.com/v4/letter/o/7c8e57/32.png) [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)\
**Post date:** [April 11, 2016, 4:04am UTC](https://discuss.elastic.co/t/question-for-aggregation/46936/1 "2016-04-11T04:04:16Z")

</div>

Hi all,

I have a requirement to aggregate related events by time.  
It can be during the indexing or during the Query.  
The time aggregation is based on a moving window, for example 1 minute, which means that all events from the same source and same type and occurred in less than 1 minute from one another are related.

For example, the following:  
Target1 Type1 15:41:35  
Target1 Type1 15:42:13  
Target1 Type1 15:42:27  
Target1 Type1 15:42:47  
Target1 Type1 15:42:57  
Target1 Type1 15:43:27

Are all related events, which needs to be aggregated.  
On aggregation I will have to take the max(timestamp).

Any Idea on how can be implemented with Elasticsearch, on Index time or Query time ?

Thanks,

Ori

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:00pm UTC](https://discuss.elastic.co/t/question-for-aggregation/46936/2 "2017-07-05T23:00:51Z")

</div>


