# Statistics using ES on group of data

**URL:** https://discuss.elastic.co/t/statistics-using-es-on-group-of-data/13441
**Category:** Elasticsearch
**Created:** [September 3, 2013, 9:54am UTC](https://discuss.elastic.co/t/statistics-using-es-on-group-of-data/13441 "2013-09-03T09:54:26Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)
#### Post date: [September 3, 2013, 9:54am UTC](https://discuss.elastic.co/t/statistics-using-es-on-group-of-data/13441/1 "2013-09-03T09:54:26Z")

</div>

Hello,  
we already set up an Elasticsearch node with Kibana on top for log analysis.

Now, we would like to make it more scalable.

I have few questions about ES and I would like to hear some  
opinions/hints/suggestions from you.

- How can we exploit quite good machines such as (24cores, 48GB RAM  
etc...) with ES? With Java 32bit the heap can be set at 2GB MAX...
- Our architecture is a message oriented distributed platform.
  - Our idea is to make each node of this platform log the properties  
of the transaction
  - We would like to obtain statistics on differend properties by group  
of linked transactions (and perform drill down on those properties)
    - E.g.
      - Data:
        - Service X(time:4;type:abc) -\> Service  
Y(time:9;type:abc) -\> Service W(time:1;type:zzz)
        - Service X(time:3;type:abc) -\> Service  
Y(time:7;type:abc) -\> Service W(time:1;type:zzz)
        - Service X(time:3;type:abc) -\> Service  
Y(time:7;type:abc) -\> Service W(time:1;type:zzz)
        - Service A(time:3;type:abc) -\> Service  
B(time:7;type:abc) -\> Service X(time:1;type:zzz) -\> Service  
Y(time:9;type:abc) -\> Service W(time:1;type:zzz)

      - Queries:
        - a) Mean of property(time) for all the transactions started  
by X
        - b) List and Mean of types of property(type) for all the  
transactions started by X

      - Expected reply:
        - a) ((4+9+1), (3+7+1), (3+7+1), (1+9+1)) / 4
        - b) ((type: abc count: 2), (type: zzz count:1)),  
((type: abc count: 2), (type: zzz count:1)),  
((type: abc count: 2), (type: zzz count:1)),  
((type: abc count: 1), (type: zzz count:2)):  
((type: abc mean: 7/4), (type: zzz count:5/4))

      - In my opinion, I should go with nested documents or find a  
way to be able to group those transactions.

What do you think about it?  
Luca

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 2:18am UTC](https://discuss.elastic.co/t/statistics-using-es-on-group-of-data/13441/2 "2017-07-06T02:18:24Z")

</div>


