# Return result of a custom field using query\_template

**URL:** <https://discuss.elastic.co/t/return-result-of-a-custom-field-using-query-template/279051>\
**Category:** Logstash\
**Created:** [July 19, 2021, 11:41am UTC](https://discuss.elastic.co/t/return-result-of-a-custom-field-using-query-template/279051 "2021-07-19T11:41:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![martb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martb/32/78185_2.png) [@martb](https://discuss.elastic.co/u/martb)\
**Post date:** [July 19, 2021, 11:41am UTC](https://discuss.elastic.co/t/return-result-of-a-custom-field-using-query-template/279051/1 "2021-07-19T11:41:17Z")

</div>

Hi,

I've created a query\_template that gets the average number of alerts per day, but it's not returning the avg\_count result to logstash. I done this before when the field exists but not with a custom result i.e not a field.  
How do I return the avg\_count valuse back to logstash?  
The query does return avg\_count when tested in Dev Tools.

**Logstash extract** :  
if [almcustomer] =~ ".+" {  
elasticsearch {  
hosts =\> "[http://127.0.0.1:9200](http://127.0.0.1:9200)"  
user =\> "user"  
password =\> "password}"  
index =\> ["acsc-main-alerts-\*"]  
query\_template =\> "/etc/logstash/conf.d/query\_templates/query\_average\_alerts\_per\_day.json"  
result\_size =\> 1  
fields =\> { "[avg\_count]" =\> "average\_alerts\_per\_day" }  
}  
}

**Query template (query\_average\_alerts\_per\_day.json)**:  
{  
"query": {  
"bool": {  
"must": ,  
"filter":   
}  
},  
"aggs": {  
"groupBy": {  
"terms": {  
"field": "almcustomer"  
},  
"aggs": {  
"docs\_per\_day": {  
"date\_histogram": {  
"field": "@timestamp",  
"fixed\_interval": "1d"  
}  
},  
"avg\_count": {  
"avg\_bucket": {  
"buckets\_path": "docs\_per\_day\>\_count"  
}  
}  
}  
}  
}  
}

**Dev Tools Result:**

{  
"took" : 0,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 2,  
"successful" : 2,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : {  
"value" : 310,  
"relation" : "eq"  
},  
"max\_score" : null,  
"hits" :   
},  
"aggregations" : {  
"groupBy" : {  
"doc\_count\_error\_upper\_bound" : 0,  
"sum\_other\_doc\_count" : 0,  
"buckets" : [  
{  
"key" : "ALM",  
"doc\_count" : 310,  
"docs\_per\_day" : {  
"buckets" : [  
{  
"key\_as\_string" : "2021-07-08T00:00:00.000Z",  
"key" : 1625702400000,  
"doc\_count" : 6  
},  
{  
"key\_as\_string" : "2021-07-09T00:00:00.000Z",  
"key" : 1625788800000,  
"doc\_count" : 304  
}  
]  
},  
"avg\_count" : {  
"value" : 155.0  
}  
}  
]  
}  
}  
}

many thanks

Martin

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2021, 11:41am UTC](https://discuss.elastic.co/t/return-result-of-a-custom-field-using-query-template/279051/2 "2021-08-16T11:41:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
