Date range aggregation

Date range aggregation #

A multi-bucket aggregation like range, but for date fields. Each bucket is a from/to interval; bounds accept epoch milliseconds.

Example #

Split logs at 2024-06-16 (epoch millis 1718534400000):

The query narrows the scope to the second half of June; the first bucket is then empty and the second holds every scoped log.

Parameters for date_range #

  • field
    (Required, string) Date field you wish to aggregate.
  • ranges
    (Required, object array) Buckets with optional from / to (epoch millis). key names a bucket.
  • format
    (Optional, string) Date format for rendering key_as_string.
Calendar September 26, 2026
Edit Edit this page