# Save results from aggregation to new index?

**URL:** <https://discuss.elastic.co/t/save-results-from-aggregation-to-new-index/86913>\
**Category:** Elasticsearch\
**Created:** [May 24, 2017, 8:00am UTC](https://discuss.elastic.co/t/save-results-from-aggregation-to-new-index/86913 "2017-05-24T08:00:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [May 24, 2017, 8:00am UTC](https://discuss.elastic.co/t/save-results-from-aggregation-to-new-index/86913/1 "2017-05-24T08:00:19Z")

</div>

Hi,

we have a log with some million events per day.  
We have a data retention time of 30 days.

Allthough we keep data accessible only for 30 days, we have the need to compare some aggregations from current month and 6 month ago.

To achieve this, we are currently doing exports / reports as screenshot / pdf / html save and then we can compare two pictures.

These logs events have fields for processing times, etc. which are aggregated to avg processing time graphs in kibana.

Because I begin to love the timelion offset functionality, I am thinking of a new way of keeping the data, but I need your help to tell me if it is possible and how it can be done.

Question:  
Is it possible via elasticsearch to run the aggregation mentioned above and store the results as new events in a different elasticseaerch index?

sample aggregation:  
bucket 1: time (interval 30 minutes)  
bucket 2: term (on function.keyword, size 20)  
aggregation: avg

If I run this in ES, it should give me an aggregated value each 30 minutes for the top 20 functions.  
Now I like to store these results in the index "preaccumulated-data-history".  
fields which are need to be stored:

- avg (result)
- function.keyword
- @timestamp

The new index should be massively smaller than the original index. I can access it via timelion and can compare current month with the current month 1 year ago.

Or are there better practices?  
Thanks, Andreas

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 24, 2017, 8:42am UTC](https://discuss.elastic.co/t/save-results-from-aggregation-to-new-index/86913/2 "2017-05-24T08:42:34Z")

</div>

You can do this using a Watch to query and then post to a new index. Otherwise any other sort of client that can run an agg and then post the outputs to ES would work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2017, 8:42am UTC](https://discuss.elastic.co/t/save-results-from-aggregation-to-new-index/86913/3 "2017-06-21T08:42:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
