# Trying to aggregate marvel watch data

**URL:** <https://discuss.elastic.co/t/trying-to-aggregate-marvel-watch-data/60227>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 10, 2016, 10:57pm UTC](https://discuss.elastic.co/t/trying-to-aggregate-marvel-watch-data/60227 "2016-09-10T22:57:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![casieowen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/casieowen/32/8734_2.png) [@casieowen](https://discuss.elastic.co/u/casieowen)\
**Post date:** [September 10, 2016, 10:57pm UTC](https://discuss.elastic.co/t/trying-to-aggregate-marvel-watch-data/60227/1 "2016-09-10T22:57:37Z")

</div>

I think this question isn't really specific to watcher, it's more a DSL question, I believe. Anyway, I've got watchers watching our marvel indices indexing the payload. Now I'm trying to aggregations on that data. I'm sure it's a simple order/syntax problem but I've looked all over and i'm not finding the answer.

Here's the query I've got:  
GET watch\_gcoldcollectioncount/\_search  
{  
"aggs": {  
"group\_by\_key": {  
"terms": {  
"field": "aggregations.minutes.buckets.nodes.buckets.key"  
},  
"aggs": {  
"average\_memory": {  
"avg": {  
"field": "aggregations.minutes.buckets.nodes.buckets.gcold.value"  
}  
}  
}  
}  
}  
}

It is returning two types of output.

1. this, for every hit:

{  
"key\_as\_string": "2016-09-10T21:33:00.000Z",  
"doc\_count": 11,  
"nodes": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets": [  
{  
"gcold": {  
"value": 2054  
},  
"doc\_count": 1,  
"key": "nodeesd0"  
},  
{  
"gcold": {  
"value": 1923  
},  
"doc\_count": 1,  
"key": "nodeesd2"  
},  
etc.  
2. The aggregations, but it's reporting the same value for every node.

"aggregations": {  
"group\_by\_key": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 8,  
"buckets": [  
{  
"key": "nodeesc0",  
"doc\_count": 5,  
"average\_memory": {  
"value": 1514.4772727272727  
}  
},  
{  
"key": "nodeesc2",  
"doc\_count": 5,  
"average\_memory": {  
"value": 1514.4772727272727  
}  
},  
{  
"key": "nodeesd0",  
"doc\_count": 5,  
"average\_memory": {  
"value": 1514.4772727272727  
}  
},  
etc.

Any help would be appreciated!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 12, 2016, 11:45am UTC](https://discuss.elastic.co/t/trying-to-aggregate-marvel-watch-data/60227/2 "2016-09-12T11:45:08Z")

</div>

Hey Casie,

first, it would be awesome to format your code snippets, which makes it much more easier for others to read. See [https://github.com/adam-p/markdown-here/wiki/Markdown-Cheatsheet#code-and-syntax-highlighting](https://github.com/adam-p/markdown-here/wiki/Markdown-Cheatsheet#code-and-syntax-highlighting)

Can you provide a sample document you are aggregating on? My (totally unproven) assumption is that you might try to aggregate across an array based data structure without using the `nested` type.

--Alex

---

<div class="post-metadata">

**Author:** ![casieowen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/casieowen/32/8734_2.png) [@casieowen](https://discuss.elastic.co/u/casieowen)\
**Post date:** [September 13, 2016, 6:15pm UTC](https://discuss.elastic.co/t/trying-to-aggregate-marvel-watch-data/60227/3 "2016-09-13T18:15:01Z")

</div>

Thanks for the reply. I got the problem figured out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/trying-to-aggregate-marvel-watch-data/60227/4 "2017-07-06T13:42:58Z")

</div>


