date_histogram
Aggregate document counts over time using a date field. Specify index, date field, and interval to get time buckets with counts.
Instructions
Get document counts over time (date histogram).
Args: index: Index to aggregate. field: Date field to aggregate on (e.g., "@timestamp"). interval: Time interval (minute, hour, day, week, month, year). query: Optional query to filter documents.
Returns: Time buckets with document counts.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| index | Yes | ||
| field | Yes | ||
| interval | No | day | |
| query | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||