# A way to modify a scripted buckets agg query to only return only specific aggregation values rather than all of them?

**URL:** <https://discuss.elastic.co/t/a-way-to-modify-a-scripted-buckets-agg-query-to-only-return-only-specific-aggregation-values-rather-than-all-of-them/80343>\
**Category:** Elasticsearch\
**Created:** [March 28, 2017, 6:16pm UTC](https://discuss.elastic.co/t/a-way-to-modify-a-scripted-buckets-agg-query-to-only-return-only-specific-aggregation-values-rather-than-all-of-them/80343 "2017-03-28T18:16:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![casieowen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/casieowen/32/8734_2.png) [@casieowen](https://discuss.elastic.co/u/casieowen)\
**Post date:** [March 28, 2017, 6:16pm UTC](https://discuss.elastic.co/t/a-way-to-modify-a-scripted-buckets-agg-query-to-only-return-only-specific-aggregation-values-rather-than-all-of-them/80343/1 "2017-03-28T18:16:41Z")

</div>

Hi!

For this query:

```auto
GET pipetemplate1/_search
{
  "size": 0,
  "_source": "averageavailabilityforxxxxupdateservice_ws_xps.value", 
  "query": {
    "wildcard": {
      "instance": "*xxxxupdateservice|ws_xps"
      }
    },
  "aggs": {
    "histogram": {
      "date_histogram": {
        "field": "date",
        "interval": "minute"
      },
      "aggs": {
        "xxxxupdateservice_ws_xps_total": {
          "filter": {
            "prefix": {
              "instance": "requests|total"
            }
          },
          "aggs": {
            "avg": {
              "avg": {
                "field": "value"
              }
            }
          }
        },
        "xxxxupdateservice_ws_xps_5xx": {
          "filter": {
            "prefix": {
              "instance": "requests|5xx"
            }
          },
          "aggs": {
            "avg": {
              "sum": {
                "field": "value"
              }
            }
          }
        },
        "averageavailabilityforxxxxupdateservice_ws_xps": {
          "bucket_script": {
            "buckets_path": {
              "failurecount": "xxxxupdateservice_ws_xps_5xx>avg",
              "totalcount": "xxxxupdateservice_ws_xps_total>avg"
            },
            "script": "(params.totalcount-params.failurecount) / params.totalcount *100"
          }
        }
      }
    }
  }
}

```

I get results like this:

```auto
  "aggregations": {
    "histogram": {
      "buckets": [
        {
          "key_as_string": "2017-03-01T00:00:00.000Z",
          "key": 1488326400000,
          "doc_count": 4,
          "xxxxupdateservice_ws_xps_5xx": {
            "doc_count": 2,
            "avg": {
              "value": 0
            }
          },
          "xxxxupdateservice_ws_xps_total": {
            "doc_count": 2,
            "avg": {
              "value": 33.28715
            }
          },
          "averageavailabilityforxxxxupdateservice_ws_xps": {
            "value": 100
          }
        },

```

Is there a way to modify the query so that it only returns the last agg value:

```auto
   "averageavailabilityforxxxxupdateservice_ws_xps": 
            "value": 100

```

Thanks,  
Casie

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [March 29, 2017, 7:37am UTC](https://discuss.elastic.co/t/a-way-to-modify-a-scripted-buckets-agg-query-to-only-return-only-specific-aggregation-values-rather-than-all-of-them/80343/2 "2017-03-29T07:37:52Z")

</div>

There is no way to do that. One work-around might be to use the response-filtering option that all APIs support, which performs filtering at the json level: [https://www.elastic.co/guide/en/elasticsearch/reference/current/common-options.html#common-options-response-filtering](https://www.elastic.co/guide/en/elasticsearch/reference/current/common-options.html#common-options-response-filtering)

---

<div class="post-metadata">

**Author:** ![casieowen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/casieowen/32/8734_2.png) [@casieowen](https://discuss.elastic.co/u/casieowen)\
**Post date:** [March 29, 2017, 4:27pm UTC](https://discuss.elastic.co/t/a-way-to-modify-a-scripted-buckets-agg-query-to-only-return-only-specific-aggregation-values-rather-than-all-of-them/80343/3 "2017-03-29T16:27:24Z")

</div>

That works!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2017, 4:27pm UTC](https://discuss.elastic.co/t/a-way-to-modify-a-scripted-buckets-agg-query-to-only-return-only-specific-aggregation-values-rather-than-all-of-them/80343/4 "2017-04-26T16:27:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
