# Rollups for beats?

**URL:** <https://discuss.elastic.co/t/rollups-for-beats/135951>\
**Category:** Beats\
**Created:** [June 14, 2018, 3:06pm UTC](https://discuss.elastic.co/t/rollups-for-beats/135951 "2018-06-14T15:06:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![christopher-b](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christopher-b/32/32276_2.png) [@christopher-b](https://discuss.elastic.co/u/christopher-b)\
**Post date:** [June 14, 2018, 3:06pm UTC](https://discuss.elastic.co/t/rollups-for-beats/135951/1 "2018-06-14T15:06:09Z")

</div>

Now that Elastic Stack 6.3 has shipped with the Rollups API, I'm wondering if there is any plan to develop a set of "default" or jumping-off point rollup configs for Beats. I'm sure many people would like to rollup their beat indices to save space (I'm looking at you, packetbeat). I'm having a bit of a hard time wrapping my head around the best way to configure the rollups, especially with the heterogeneous documents that some beats generate.

Thoughts? Thanks.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 15, 2018, 7:29am UTC](https://discuss.elastic.co/t/rollups-for-beats/135951/2 "2018-06-15T07:29:38Z")

</div>

We definitively have some plans around providing jobs / templates examples that can be reused. Here is a first PR to discuss it: [https://github.com/elastic/beats/pull/7220](https://github.com/elastic/beats/pull/7220) But it also has some blocker from the Beats perspective as you can see in the PR description.

Would be great to hear from you on what you would expect on how Beats would load rollups and on how you would expect the workflow from a user perspective.

---

<div class="post-metadata">

**Author:** ![christopher-b](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christopher-b/32/32276_2.png) [@christopher-b](https://discuss.elastic.co/u/christopher-b)\
**Post date:** [June 20, 2018, 1:04pm UTC](https://discuss.elastic.co/t/rollups-for-beats/135951/3 "2018-06-20T13:04:24Z")

</div>

Sounds great.

At a minimum, I would like to see some example rollup jobs that I could send to my elasticsearch instance.

I'm new to elasticsearch and I don't want to spend a ton of time making decisions about which fields I need to group on and which metrics to collect, but it would be nice to be able to say "I know I will never need metric x, discard it".

I would also want to customize rollup resolution. My point of reference is graphite, where you can easily configure multiple tiers of data resolution. For example, after 1 day, reduce resolution to 10s, after 7 days reduce to one minute, etc.

It would also be great to put this in the beats config file and have the beat process create the rollup jobs for me.

The default dashboards should be rollup-aware.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 22, 2018, 6:22am UTC](https://discuss.elastic.co/t/rollups-for-beats/135951/4 "2018-06-22T06:22:16Z")

</div>

@christopher-b Thanks a lot for sharing your expected behaviour here. Appreciate it.

---

<div class="post-metadata">

**Author:** ![fozboz](https://avatars.discourse-cdn.com/v4/letter/f/df788c/32.png) [@fozboz](https://discuss.elastic.co/u/fozboz)\
**Post date:** [July 11, 2018, 5:23pm UTC](https://discuss.elastic.co/t/rollups-for-beats/135951/5 "2018-07-11T17:23:38Z")

</div>

I too would love to see something like this. There are 1,295 fields in my metricbeat indices and creating the groups and metrics for all of those seems like a monumental and tedious task.

It would be nice to just say `please give me 5 minute averages for everything`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2018, 7:23pm UTC](https://discuss.elastic.co/t/rollups-for-beats/135951/6 "2018-08-08T19:23:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
