# Sub aggregation on dynamically calculated field

**URL:** <https://discuss.elastic.co/t/sub-aggregation-on-dynamically-calculated-field/48072>\
**Category:** Elasticsearch\
**Created:** [April 21, 2016, 3:54pm UTC](https://discuss.elastic.co/t/sub-aggregation-on-dynamically-calculated-field/48072 "2016-04-21T15:54:59Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cynosureabu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cynosureabu/32/47196_2.png) [@cynosureabu](https://discuss.elastic.co/u/cynosureabu)\
**Post date:** [April 21, 2016, 3:54pm UTC](https://discuss.elastic.co/t/sub-aggregation-on-dynamically-calculated-field/48072/1 "2016-04-21T15:54:59Z")

</div>

I have a date\_histogram aggregation first, however, I then wanna find out the count based on another field, which is calculated on the date in the result of date\_histogram:

my document has the following structure:

{  
name: 'test'  
event\_time: 2015-04-01,  
activity\_stream:{  
2015-04-02: {'login':3, "openfile":5}  
2015-04-04: {'login':2, "openfile":7}  
.....  
}  
}

I essentially would need something like:  
"aggregations": {  
"by\_day": {  
"date\_histogram": {  
"field": "event\_time",  
"interval": "day"  
},  
"aggregations": {  
"day\_1":{  
"filter": {  
"range": {  
"activity\_stream.{ **DYNAMIC\_FIELD** }.login": {  
"gt": 0  
}  
}  
}  
},  
"day\_2":{  
}  
}  
}  
}

The DYNAMIC\_FIELD need to be calculated based on the date in the bucket of the date\_histogram: I wanna find out on each day, how many users have loggedin in next 1,2,3 days.

Anyway to achieve this?

Chen

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:57pm UTC](https://discuss.elastic.co/t/sub-aggregation-on-dynamically-calculated-field/48072/2 "2017-07-05T22:57:15Z")

</div>


