# Save storage with aggregation log

**URL:** <https://discuss.elastic.co/t/save-storage-with-aggregation-log/175019>\
**Category:** Elasticsearch\
**Created:** [April 2, 2019, 2:27pm UTC](https://discuss.elastic.co/t/save-storage-with-aggregation-log/175019 "2019-04-02T14:27:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![elk2](https://avatars.discourse-cdn.com/v4/letter/e/f14d63/32.png) [@elk2](https://discuss.elastic.co/u/elk2)\
**Post date:** [April 2, 2019, 2:27pm UTC](https://discuss.elastic.co/t/save-storage-with-aggregation-log/175019/1 "2019-04-02T14:27:22Z")

</div>

I have many data stored into elasticsearch but I want only statistics values.  
Example:

```
64.242.88.10 - - [07/Mar/2004:16:05:49 -0800] "GET /twiki/bin/edit/Main/Double_bounce_sender?topicparent=Main.ConfigurationVariables HTTP/1.1" 401 12846

```

64.242.88.10 - - [07/Mar/2004:16:06:51 -0800] "GET /twiki/bin/rdiff/TWiki/NewUserTemplate?rev1=1.3&rev2=1.2 HTTP/1.1" 200 4523  
64.242.88.10 - - [07/Mar/2004:16:10:02 -0800] "GET /mailman/listinfo/hsdivision HTTP/1.1" 200 6291  
64.242.88.10 - - [07/Mar/2004:16:11:58 -0800] "GET /twiki/bin/view/TWiki/WikiSyntax HTTP/1.1" 200 7352  
64.242.88.10 - - [07/Mar/2004:16:20:55 -0800] "GET /twiki/bin/view/Main/DCCAndPostFix HTTP/1.1" 200 5253  
64.242.88.10 - - [07/Mar/2004:16:23:12 -0800] "GET /twiki/bin/oops/TWiki/AppendixFileSystem?template=oopsmore¶m1=1.12¶m2=1.12 HTTP/1.1" 200 11382  
64.242.88.10 - - [07/Mar/2004:16:24:16 -0800] "GET /twiki/bin/view/Main/PeterThoeny HTTP/1.1" 200 4924  
64.242.88.10 - - [07/Mar/2004:16:29:16 -0800] "GET /twiki/bin/edit/Main/Header\_checks?topicparent=Main.ConfigurationVariables HTTP/1.1" 401 12851  
64.242.88.10 - - [07/Mar/2004:16:30:29 -0800] "GET /twiki/bin/attach/Main/OfficeLocations HTTP/1.1" 401 12851  
64.242.88.10 - - [07/Mar/2004:16:31:48 -0800] "GET /twiki/bin/view/TWiki/WebTopicEditTemplate HTTP/1.1" 200 3732

I want to store online 1 log like this:  
64.242.88.10 - - [07/Mar/2004] "GET\_COUNTS=10"

I have to create a new index and query data or there is another way?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2019, 2:27pm UTC](https://discuss.elastic.co/t/save-storage-with-aggregation-log/175019/2 "2019-04-30T14:27:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
