# Rollup - Date Histogram aggregation

**URL:** <https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308>\
**Category:** Elasticsearch\
**Created:** [August 28, 2018, 9:42am UTC](https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308 "2018-08-28T09:42:22Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Steven\_Liu](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@Steven\_Liu](https://discuss.elastic.co/u/Steven_Liu)\
**Post date:** [August 28, 2018, 9:42am UTC](https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308/1 "2018-08-28T09:42:22Z")

</div>

Hi Guys

I have a rollup index (interval: 1d) created. But when do \_rollup\_search, I cannot use date histogram aggregation for larger interval (e.g. 1M, 1y). Only let me use 1d as defined in the rollup job config. Any ideas?

Cheers  
Steve

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [August 28, 2018, 3:30pm UTC](https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308/2 "2018-08-28T15:30:29Z")

</div>

Hi @Steven_Liu. Do you mean an exception is thrown, or it just doesn't show results/results are empty?

Note that there is a difference in calendar vs. fixed time (unfortunately). We're [working on a PR](https://github.com/elastic/elasticsearch/pull/32052) to make this clearer in Rollup. I'm not sure if that's what you're running into, but wanted to mention.

---

<div class="post-metadata">

**Author:** ![Steven\_Liu](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@Steven\_Liu](https://discuss.elastic.co/u/Steven_Liu)\
**Post date:** [August 29, 2018, 8:44am UTC](https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308/3 "2018-08-29T08:44:10Z")

</div>

Thanks for the reply @polyfractal .

I got the exception thrown once using data histogram other than 1d:

```auto
{
    "error": {
        "root_cause": [
            {
                "type": "illegal_argument_exception",
                "reason": "failed to parse setting [source.date_histogram.interval] with value [1M] as a time value: unit is missing or unrecognized"
            }
        ],
        "type": "illegal_argument_exception",
        "reason": "failed to parse setting [source.date_histogram.interval] with value [1M] as a time value: unit is missing or unrecognized"
    },
    "status": 400
}

```

I was trying to run \_rollup\_search and aggregate my daily rollup index into monthly. It worked only if use 'Days' (e.g. 1d or 30d) interval which is the same as in rollup group config. I read this link [https://www.elastic.co/guide/en/elasticsearch/reference/current/\_rollup\_is\_multi\_interval\_aware.html](http://_rollup_is_multi_interval_aware) thought it is possible to aggregate with lower granular in 6.4??

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [August 29, 2018, 5:59pm UTC](https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308/4 "2018-08-29T17:59:22Z")

</div>

Hm, not sure off the top of my head. You're correct, it should be possible to aggregate with larger intervals.

Could you paste the Rollup config, the query, and the exception full stack trace? I want to try and recreate on my side to make investigating easier.

Thanks!

---

<div class="post-metadata">

**Author:** ![Steven\_Liu](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@Steven\_Liu](https://discuss.elastic.co/u/Steven_Liu)\
**Post date:** [August 30, 2018, 7:33am UTC](https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308/5 "2018-08-30T07:33:58Z")

</div>

Cheers @polyfractal

My rollup config:

```auto
{
    "index_pattern": "payment_index",
    "rollup_index": "payment_rollup_index",
    "cron": "0 0/1 * 1/1 * ? *",
    "page_size" :1000,
    "groups" : {
      "date_histogram": {
        "field": "aud_datetime",
        "interval": "1d"
      },
      "terms": {
        "fields": ["cust_id", "payment_type", "payment_status"]
      }
    },
    "metrics": [
        {
            "field": "payment_amount_gbp",
            "metrics": ["min", "max", "sum","avg"]
        }
    ]
}

```

Search query:

```auto
{
  "size": 0,
  "aggs": {
  	"group_by_cust": {
        "terms": {
            "field": "cust_id"
        },
        "aggs": {
	        "payment": {
		    	"date_histogram": {
			    	"field": "aud_datetime",
			        "interval": "1M"
					},
					"aggs": {
				    	"total": {
				        	"sum": {
		            		"field": "payment_amount_gbp"
		        			}
				        }
		        		
		        	}
		    	}
    		}
		}
	}
}

```

As mentioned, I would like to create a monthly rollup index. However, I cannot use '1M' as data histogram interval. It through the same error.

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [August 30, 2018, 1:35pm UTC](https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308/6 "2018-08-30T13:35:37Z")

</div>

👍 roger, thanks for the config. Will poke at this on my end and get back to you.

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [August 30, 2018, 7:53pm UTC](https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308/7 "2018-08-30T19:53:28Z")

</div>

Heya @Steven_Liu, found the issue. There is a bug in the validation code that tries to parse all request intervals as "fixed" time, which is why it fails for your calendar time `1M` or `month`.

This was fixed in the refactor from [https://github.com/elastic/elasticsearch/pull/32052](https://github.com/elastic/elasticsearch/pull/32052). I went ahead and opened a new PR to backport the fix to 6.4.1: [https://github.com/elastic/elasticsearch/pull/33284](https://github.com/elastic/elasticsearch/pull/33284)

For now, the fix is as you said: use a lower granularity value to express the month, like `30d`. This is only sorta a fix though, because `30d` is a "fixed" interval whereas `1M` can change duration depending on _which_ month. That's the impetus for the #32052 PR... to make the difference clear because it is confusing and trappy for users.

Even after the fix is backported and 6.4.1 released, I would encourage using only "fixed" time intervals. So instead of rolling up `1M`, I would configure it to rollup `30d`. You'll lose calendar aspects of variable-days-per-month, but gain a ton of querying flexibility. Calendar units are only available in "single" quantities (`1d`, `1w`, `1M`, `1q`, `1Y`), whereas fixed units allow multiples (`5d`, `100s`, `2M`, etc).

See the new 6.x docs [here](https://www.elastic.co/guide/en/elasticsearch/reference/6.x/rollup-search-limitations.html#_interval_granularity) and [here (under "Calendar vs Fixed Time Intervals")](https://www.elastic.co/guide/en/elasticsearch/reference/6.x/rollup-job-config.html#_date_histogram_2) for some more explanation.

---

<div class="post-metadata">

**Author:** ![Steven\_Liu](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@Steven\_Liu](https://discuss.elastic.co/u/Steven_Liu)\
**Post date:** [September 3, 2018, 6:46am UTC](https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308/8 "2018-09-03T06:46:08Z")

</div>

Cheers @polyfractal. That makes a log sense now. Thanks very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2018, 6:53am UTC](https://discuss.elastic.co/t/rollup-date-histogram-aggregation/146308/9 "2018-10-01T06:53:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
