获取 date_histogram 的桶平均值,Elasticsearch

5

我有以下查询,获取数据并创建每个过去小时的聚合:

    query = {
        "query": {
            "bool": {          
                "must": [
                    { "term": {"deviceId":device} },
                    { "match": {"eventType":"Connected"} } 
                ],
                "must_not":[{
                        "query_string": {
                            "query": "Pong",
                            "fields": ["data.message"]
                        }
                    },
                ] 
            },

        },
        "size": 0,
        "sort": [{ "timestamp": { "order": "desc" }}],
        "aggs" : {
            "time_buckets" : {
                "date_histogram" : {
                    "field" : "timestamp",
                    "interval" : "hour",

                },
            }
        }
    }

我希望能够从每个小时间隔(聚合创建的每个存储桶)中获取一个字段的平均值。在这篇文章中,他们讨论了与我想要做的类似的事情:http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/_looking_at_time.html(“上周我们网站每小时的平均延迟是多少?”)。然而,他们没有详细说明在这种情况下该怎么做。请问有人知道如何做吗?
1个回答

11

刚意识到我可以进行嵌套聚合,然后在聚合内计算字段的平均值。这是我的做法,并且现在正常运行:

 query = {
            "query": {
                "bool": {          
                    "must": [
                        { "term": {"deviceId":device} },
                        { "match": {"eventType":"Connected"} } 
                    ],
                    "must_not":[{
                            "query_string": {
                                "query": "Pong",
                                "fields": ["data.message"]
                            }
                        },
                    ] 
                },

            },
            "size": 0,
            "sort": [{ "timestamp": { "order": "desc" }}],
            "aggs" : {
                "time_buckets" : {
                    "date_histogram" : {
                        "field" : "timestamp",
                        "interval" : "day"
                    },
                    "aggs" : {
                        "avg_battery" : {
                            "avg": { "field": "data.battery-level" } 
                        }
                    }
                }
            }
        }

网页内容由stack overflow 提供, 点击上面的
可以查看英文原文,
原文链接