Lesson 4 — Aggregations #
From counts to histograms to composite paging — over sales and logs,
with known answers you can verify by hand.
Metric aggregations #
One number out:
sum,
avg, min, max,
stats (all of them at once),
cardinality (distinct
values):
Four distinct product types; stats gives you min/max/sum/avg/count in one
round trip.
Bucket aggregations #
terms builds a bucket per value —
the dataset’s known answer is t-shirt 60, hat 30, mug 20, sticker 10:
histogram slices a number into
fixed intervals;
date_histogram
slices time — 92 sales in 2024, 28 in 2025:
Sub-aggregations #
Every bucket runs its own aggs — revenue per type as sum of price
inside a terms bucket:
Filtered aggregations #
filter scopes an aggregation to a
query;
filters builds named
buckets — the logs level split (error 25 / warn 25 / info 100):
Paging through buckets #
composite pages through
multi-dimensional buckets with an after cursor — for dashboards, not top-10
lists:
What you learned #
- Metric aggs summarize; bucket aggs group; sub-
aggsnest. size: 0skips hit assembly — the aggregations ARE the result.composite+aftercursors for complete bucket walks.