# Timeshift functionality in Elasticsearch

**URL:** <https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585>\
**Category:** Elasticsearch\
**Created:** [June 12, 2015, 3:34pm UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585 "2015-06-12T15:34:00Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![trekr5](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@trekr5](https://discuss.elastic.co/u/trekr5)\
**Post date:** [June 12, 2015, 3:34pm UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/1 "2015-06-12T15:34:01Z")

</div>

Hello,

Is there a way, in Elasticsearch, to compare current values against values in another time period .i.e, finding the current value of status 500 errors against the same value 24 hours ago in order to create a trend based graph in a dashboard?

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 14, 2015, 2:43am UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/2 "2015-06-14T02:43:50Z")

</div>

Kibana does this, it's a date aggregation.  
If you get what you want working in KB then it's simple to just copy the query you want 🙂

---

<div class="post-metadata">

**Author:** ![trekr5](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@trekr5](https://discuss.elastic.co/u/trekr5)\
**Post date:** [June 15, 2015, 10:54am UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/3 "2015-06-15T10:54:20Z")

</div>

so would that be for the date aggregation...

"aggs"=\> {  
"0"=\> {  
"date\_histogram"=\> {  
"field"=\> "@timestamp",  
"interval"=\> "day"  
}  
}  
},  
"size"=\> 0  
}

I'm using this query in a ruby script so I'm trying to find the a value for a metric now and what it was 24 hours ago. I tried it using the Kibana dashboard using the date range "gt" =\> "-25h", "lt" =\> "-24h" but this didn't work. The metric I'm trying to find is that of value of a metric over a rolling hour and comparing that to the same metric's value over 24 hours ago.

I'd appreciate any assistance.

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [June 15, 2015, 1:52pm UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/4 "2015-06-15T13:52:37Z")

</div>

The short answer is that it isn't possible in Elasticsearch _yet_, but we're working on it. There is a PR open which adds a "serial differencing" aggregation to the new set of Pipeline aggs in 2.0:

> <https://github.com/elastic/elasticsearch/pull/11196>

You build a histo or date\_histo, then embed the new `diff` agg inside of the histogram and specify what "lag" you want differenced. So in your case, you'd specify a lag of 24hrs. The aggregation then subtracts the current point from the same point 24 hours ago and gives you back the difference.

---

<div class="post-metadata">

**Author:** ![trekr5](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@trekr5](https://discuss.elastic.co/u/trekr5)\
**Post date:** [June 15, 2015, 2:23pm UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/5 "2015-06-15T14:23:13Z")

</div>

Hi,

so would this be:-

"aggs" =\> {  
"diff"=\> {  
"date\_histrogram" =\> {  
"field"=\> "@timestamp",  
"interval" =\> "-24h"  
}  
}  
},  
"size"=\>0  
}

New to elasticsearch so please bear with me!

could I also use the interval of "-1d"?

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [June 15, 2015, 2:25pm UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/6 "2015-06-15T14:25:47Z")

</div>

Well, the PR hasn't been merged yet, so the functionality is not available. And it is reliant on new framework (called Pipeline aggregations), which won't be added until Elasticsearch 2.0.

But once the feature is merged, it should work something like this

```json
{
   "aggs": {
      "my_date_histo": {
         "date_histogram": {
            "field": "@timestamp",
            "interval": "hour"
         },
         "aggs": {
            "the_avg": {
               "avg": {
                  "field": "my_field"
               }
            },
            "twenty_four_hours_diff": {
               "diff": {
                  "buckets_path": "the_avg",
                  "lag" : 24
               }
            }
         }
      }
   }
}

```

---

<div class="post-metadata">

**Author:** ![trekr5](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@trekr5](https://discuss.elastic.co/u/trekr5)\
**Post date:** [June 15, 2015, 2:41pm UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/7 "2015-06-15T14:41:42Z")

</div>

so what could i use in my code now to get this value?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 15, 2015, 10:11pm UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/8 "2015-06-15T22:11:49Z")

</div>

As @polyfractal mentioned, you cannot do this at the moment.

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [June 16, 2015, 11:27am UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/9 "2015-06-16T11:27:46Z")

</div>

Yeah, if you need this value, the only way to do it currently is inside your own application. E.g. pull down the entire histogram, then perform the difference calculation yourself.

---

<div class="post-metadata">

**Author:** ![trekr5](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@trekr5](https://discuss.elastic.co/u/trekr5)\
**Post date:** [June 18, 2015, 2:40pm UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/10 "2015-06-18T14:40:02Z")

</div>

could i use date math for this query?

i.e. the value from the previous day would be:

"gte"=\> "now-2h" and "lte"=\> "now-2h/d"

?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:06am UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585/11 "2017-07-06T00:06:43Z")

</div>


