# Using Group By Keys to apply metric aggregation

**URL:** <https://discuss.elastic.co/t/using-group-by-keys-to-apply-metric-aggregation/271811>\
**Category:** Elasticsearch\
**Tags:** transforms\
**Created:** [April 30, 2021, 4:28pm UTC](https://discuss.elastic.co/t/using-group-by-keys-to-apply-metric-aggregation/271811 "2021-04-30T16:28:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig\_Uss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_uss/32/78413_2.png) [@Craig\_Uss](https://discuss.elastic.co/u/Craig_Uss)\
**Post date:** [April 30, 2021, 4:28pm UTC](https://discuss.elastic.co/t/using-group-by-keys-to-apply-metric-aggregation/271811/1 "2021-04-30T16:28:20Z")

</div>

Is it possible to use an aggregation group\_by attributes in a metric aggregation to determine if the metric should be counted or not?

Here is an example:  
Index of documents: Schema

```auto
    @timestamp - UTC Timestamp
    customer_id - A123
    thread_topics - Object array
        id - 12345
        type - could be one of ['news' , 'faq']
        name - 'ELK News Thread'

```

Transform - T1 - Record created by date, customer id, thread\_topic name (each one found in record)

```auto
   Group by = @timestamp(1M), customer_id, thread_topics.name
   Aggregations:
        value_count_news: 
             thread_topics of type 'NEWS'
        value_count_faq:
             thread_topics of type 'FAQ'

```

Example record - INPUT

```auto
    {
    	"@timestamp": "2021-04-30T15:49:52.584Z",
    	"customer_id": "A1234",
    	"thread_topics": [
    		{
    			"id": 12345,
    			"type": "NEWS",
    			"name": "ELK News Thread"
    		},
                {
    			"id": 12347,
    			"type": "NEWS",
    			"name": "KIBANA News Thread"
    		}
    		{
    			"id": 12346,
    			"type": "FAQ",
    			"name": "ELK FAQ Thread"
    		}
    	]
    }

```

The expected output in transform:

```auto
  [
   	{
   		"@timestamp": "2021-04-30T00:00:00.000Z",
   		"customer_id": "A1234",
   		"thread_topics.name": "ELK News Thread",
   		"value_count_news": 1,
   		"value_count_faq": 0
   	},
   	{
   		"@timestamp": "2021-04-30T00:00:00.000Z",
   		"customer_id": "A1234",
   		"thread_topics.name": "KIBANA News Thread",
   		"value_count_news": 1,
   		"value_count_faq": 0
   	},
   	{
   		"@timestamp": "2021-04-30T00:00:00.000Z",
   		"customer_id": "A1234",
   		"thread_topics.name": "ELK FAQ Thread",
   		"value_count_news": 0
   	}
   ]

```

What we are actually seeing

```auto
    [
    	{
    		"@timestamp": "2021-04-30T00:00:00.000Z",
    		"customer_id": "A1234",
    		"thread_topics.name": "ELK News Thread",
    		"value_count_news": 2,
    		"value_count_faq": 0
    	},
    	{
    		"@timestamp": "2021-04-30T00:00:00.000Z",
    		"customer_id": "A1234",
    		"thread_topics.name": "KIBANA News Thread",
    		"value_count_news": 2,
    		"value_count_faq": 0
    	},
    	{
    		"@timestamp": "2021-04-30T00:00:00.000Z",
    		"customer_id": "A1234",
    		"thread_topics.name": "ELK FAQ Thread",
    		"value_count_news": 0
    		"value_count_faq": 1
    	}
    ]

```

---

<div class="post-metadata">

**Author:** ![wei.wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wei.wang/32/51803_2.png) [@wei.wang](https://discuss.elastic.co/u/wei.wang)\
**Post date:** [April 30, 2021, 5:04pm UTC](https://discuss.elastic.co/t/using-group-by-keys-to-apply-metric-aggregation/271811/2 "2021-04-30T17:04:10Z")

</div>

Hi there,

Your question is similar like this one: [Transform on fields of a nested object](https://discuss.elastic.co/t/transform-on-fields-of-a-nested-object/236986), and the background document is this: [Nested aggregation | Elasticsearch Guide [7.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-nested-aggregation.html)

As [Hendrik answered in that topic](https://discuss.elastic.co/t/transform-on-fields-of-a-nested-object/236986/4) , we don't have a date when to support it at this moment, unfortunately.

Cheers  
Wei

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2021, 5:05pm UTC](https://discuss.elastic.co/t/using-group-by-keys-to-apply-metric-aggregation/271811/3 "2021-05-28T17:05:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
