Extended stats aggregation

Extended stats aggregation

A multi-value metrics aggregation that computes stats over numeric values extracted from the aggregated documents.

The extended_stats aggregations is an extended version of the stats aggregation, where additional metrics are added such as sum_of_squares, variance, std_deviation and std_deviation_bounds.

Assuming the data consists of documents representing exams grades (between 0 and 100) of students

  1. resp = client.search(
  2. index="exams",
  3. size=0,
  4. aggs={
  5. "grades_stats": {
  6. "extended_stats": {
  7. "field": "grade"
  8. }
  9. }
  10. },
  11. )
  12. print(resp)
  1. response = client.search(
  2. index: 'exams',
  3. body: {
  4. size: 0,
  5. aggregations: {
  6. grades_stats: {
  7. extended_stats: {
  8. field: 'grade'
  9. }
  10. }
  11. }
  12. }
  13. )
  14. puts response
  1. const response = await client.search({
  2. index: "exams",
  3. size: 0,
  4. aggs: {
  5. grades_stats: {
  6. extended_stats: {
  7. field: "grade",
  8. },
  9. },
  10. },
  11. });
  12. console.log(response);
  1. GET /exams/_search
  2. {
  3. "size": 0,
  4. "aggs": {
  5. "grades_stats": { "extended_stats": { "field": "grade" } }
  6. }
  7. }

The above aggregation computes the grades statistics over all documents. The aggregation type is extended_stats and the field setting defines the numeric field of the documents the stats will be computed on. The above will return the following:

The std_deviation and variance are calculated as population metrics so they are always the same as std_deviation_population and variance_population respectively.

  1. {
  2. ...
  3. "aggregations": {
  4. "grades_stats": {
  5. "count": 2,
  6. "min": 50.0,
  7. "max": 100.0,
  8. "avg": 75.0,
  9. "sum": 150.0,
  10. "sum_of_squares": 12500.0,
  11. "variance": 625.0,
  12. "variance_population": 625.0,
  13. "variance_sampling": 1250.0,
  14. "std_deviation": 25.0,
  15. "std_deviation_population": 25.0,
  16. "std_deviation_sampling": 35.35533905932738,
  17. "std_deviation_bounds": {
  18. "upper": 125.0,
  19. "lower": 25.0,
  20. "upper_population": 125.0,
  21. "lower_population": 25.0,
  22. "upper_sampling": 145.71067811865476,
  23. "lower_sampling": 4.289321881345245
  24. }
  25. }
  26. }
  27. }

The name of the aggregation (grades_stats above) also serves as the key by which the aggregation result can be retrieved from the returned response.

Standard Deviation Bounds

By default, the extended_stats metric will return an object called std_deviation_bounds, which provides an interval of plus/minus two standard deviations from the mean. This can be a useful way to visualize variance of your data. If you want a different boundary, for example three standard deviations, you can set sigma in the request:

  1. resp = client.search(
  2. index="exams",
  3. size=0,
  4. aggs={
  5. "grades_stats": {
  6. "extended_stats": {
  7. "field": "grade",
  8. "sigma": 3
  9. }
  10. }
  11. },
  12. )
  13. print(resp)
  1. response = client.search(
  2. index: 'exams',
  3. body: {
  4. size: 0,
  5. aggregations: {
  6. grades_stats: {
  7. extended_stats: {
  8. field: 'grade',
  9. sigma: 3
  10. }
  11. }
  12. }
  13. }
  14. )
  15. puts response
  1. const response = await client.search({
  2. index: "exams",
  3. size: 0,
  4. aggs: {
  5. grades_stats: {
  6. extended_stats: {
  7. field: "grade",
  8. sigma: 3,
  9. },
  10. },
  11. },
  12. });
  13. console.log(response);
  1. GET /exams/_search
  2. {
  3. "size": 0,
  4. "aggs": {
  5. "grades_stats": {
  6. "extended_stats": {
  7. "field": "grade",
  8. "sigma": 3
  9. }
  10. }
  11. }
  12. }

sigma controls how many standard deviations +/- from the mean should be displayed

sigma can be any non-negative double, meaning you can request non-integer values such as 1.5. A value of 0 is valid, but will simply return the average for both upper and lower bounds.

The upper and lower bounds are calculated as population metrics so they are always the same as upper_population and lower_population respectively.

Standard Deviation and Bounds require normality

The standard deviation and its bounds are displayed by default, but they are not always applicable to all data-sets. Your data must be normally distributed for the metrics to make sense. The statistics behind standard deviations assumes normally distributed data, so if your data is skewed heavily left or right, the value returned will be misleading.

Script

If you need to aggregate on a value that isn’t indexed, use a runtime field. Say the we found out that the grades we’ve been working on were for an exam that was above the level of the students and we want to “correct” it:

  1. resp = client.search(
  2. index="exams",
  3. size=0,
  4. runtime_mappings={
  5. "grade.corrected": {
  6. "type": "double",
  7. "script": {
  8. "source": "emit(Math.min(100, doc['grade'].value * params.correction))",
  9. "params": {
  10. "correction": 1.2
  11. }
  12. }
  13. }
  14. },
  15. aggs={
  16. "grades_stats": {
  17. "extended_stats": {
  18. "field": "grade.corrected"
  19. }
  20. }
  21. },
  22. )
  23. print(resp)
  1. response = client.search(
  2. index: 'exams',
  3. body: {
  4. size: 0,
  5. runtime_mappings: {
  6. 'grade.corrected' => {
  7. type: 'double',
  8. script: {
  9. source: "emit(Math.min(100, doc['grade'].value * params.correction))",
  10. params: {
  11. correction: 1.2
  12. }
  13. }
  14. }
  15. },
  16. aggregations: {
  17. grades_stats: {
  18. extended_stats: {
  19. field: 'grade.corrected'
  20. }
  21. }
  22. }
  23. }
  24. )
  25. puts response
  1. const response = await client.search({
  2. index: "exams",
  3. size: 0,
  4. runtime_mappings: {
  5. "grade.corrected": {
  6. type: "double",
  7. script: {
  8. source: "emit(Math.min(100, doc['grade'].value * params.correction))",
  9. params: {
  10. correction: 1.2,
  11. },
  12. },
  13. },
  14. },
  15. aggs: {
  16. grades_stats: {
  17. extended_stats: {
  18. field: "grade.corrected",
  19. },
  20. },
  21. },
  22. });
  23. console.log(response);
  1. GET /exams/_search
  2. {
  3. "size": 0,
  4. "runtime_mappings": {
  5. "grade.corrected": {
  6. "type": "double",
  7. "script": {
  8. "source": "emit(Math.min(100, doc['grade'].value * params.correction))",
  9. "params": {
  10. "correction": 1.2
  11. }
  12. }
  13. }
  14. },
  15. "aggs": {
  16. "grades_stats": {
  17. "extended_stats": { "field": "grade.corrected" }
  18. }
  19. }
  20. }

Missing value

The missing parameter defines how documents that are missing a value should be treated. By default they will be ignored but it is also possible to treat them as if they had a value.

  1. resp = client.search(
  2. index="exams",
  3. size=0,
  4. aggs={
  5. "grades_stats": {
  6. "extended_stats": {
  7. "field": "grade",
  8. "missing": 0
  9. }
  10. }
  11. },
  12. )
  13. print(resp)
  1. response = client.search(
  2. index: 'exams',
  3. body: {
  4. size: 0,
  5. aggregations: {
  6. grades_stats: {
  7. extended_stats: {
  8. field: 'grade',
  9. missing: 0
  10. }
  11. }
  12. }
  13. }
  14. )
  15. puts response
  1. const response = await client.search({
  2. index: "exams",
  3. size: 0,
  4. aggs: {
  5. grades_stats: {
  6. extended_stats: {
  7. field: "grade",
  8. missing: 0,
  9. },
  10. },
  11. },
  12. });
  13. console.log(response);
  1. GET /exams/_search
  2. {
  3. "size": 0,
  4. "aggs": {
  5. "grades_stats": {
  6. "extended_stats": {
  7. "field": "grade",
  8. "missing": 0
  9. }
  10. }
  11. }
  12. }

Documents without a value in the grade field will fall into the same bucket as documents that have the value 0.