# Trying to aggregate data backwards in time

**URL:** <https://discuss.elastic.co/t/trying-to-aggregate-data-backwards-in-time/104124>\
**Category:** Kibana\
**Created:** [October 16, 2017, 5:00pm UTC](https://discuss.elastic.co/t/trying-to-aggregate-data-backwards-in-time/104124 "2017-10-16T17:00:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dorj1234](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorj1234/32/21339_2.png) [@dorj1234](https://discuss.elastic.co/u/dorj1234)\
**Post date:** [October 16, 2017, 5:00pm UTC](https://discuss.elastic.co/t/trying-to-aggregate-data-backwards-in-time/104124/1 "2017-10-16T17:00:17Z")

</div>

Hi, not sure if this is possible in Kibana, or even using Logstash.  
I am looking for a way to see how many VMs I have added and removed in the past month/quarter.  
Every day VMs records are kept. For each VM I keep a status "ADDED" or "REMOVED".

For example:  
After day 1, I have 10 "documents" with status "REMOVED" and 5 with status "ADDED".  
After day 2 I have the previous day count + today's count.

Now I am looking back at the last month, trying to summarize this count.  
Any suggestions?

Thanks in advance !  
JD

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [October 17, 2017, 7:20am UTC](https://discuss.elastic.co/t/trying-to-aggregate-data-backwards-in-time/104124/2 "2017-10-17T07:20:52Z")

</div>

maybe i am over simplifying this, but isn't `SUM(added) - SUM(removed)` what you are looking for ?

---

<div class="post-metadata">

**Author:** ![dorj1234](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorj1234/32/21339_2.png) [@dorj1234](https://discuss.elastic.co/u/dorj1234)\
**Post date:** [October 17, 2017, 2:39pm UTC](https://discuss.elastic.co/t/trying-to-aggregate-data-backwards-in-time/104124/3 "2017-10-17T14:39:14Z")

</div>

Close. You are right it's simpler than I thought, just used 'count' instead of 'sum' and whatever timeframe my dashboard is using displays the count numbers.  
I guess I needed to sleep on it and it was clear.

Thanks for answering !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2017, 2:41pm UTC](https://discuss.elastic.co/t/trying-to-aggregate-data-backwards-in-time/104124/4 "2017-11-14T14:41:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
