# About aggregations request with scroll, only the first results can be output?

**URL:** <https://discuss.elastic.co/t/about-aggregations-request-with-scroll-only-the-first-results-can-be-output/117300>\
**Category:** Elasticsearch\
**Created:** [January 27, 2018, 12:11pm UTC](https://discuss.elastic.co/t/about-aggregations-request-with-scroll-only-the-first-results-can-be-output/117300 "2018-01-27T12:11:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pelin\_li](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pelin_li/32/27026_2.png) [@Pelin\_li](https://discuss.elastic.co/u/Pelin_li)\
**Post date:** [January 27, 2018, 12:11pm UTC](https://discuss.elastic.co/t/about-aggregations-request-with-scroll-only-the-first-results-can-be-output/117300/1 "2018-01-27T12:11:16Z")

</div>

## Version

Elasticsearch:

```auto
"version" : {
    "number" : "5.0.0",
    "build_hash" : "253032b",
    "build_date" : "2016-10-26T05:11:34.737Z",
    "build_snapshot" : false,
    "lucene_version" : "6.2.0"
  }

```

Java:

```auto
openjdk version "1.8.0_102"

```

OS:

```auto
Linux 10-10-166-129 3.13.0-46-generic #79-Ubuntu SMP Tue Mar 10 20:06:50 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux

```

Docker(It's a old version):

```auto
Docker version 1.12.2, build bb80604

```

Also, we are using `elasticsearch:5` docker image

## Description

### What i want

I want to search 1 hour data from elasticsearch by `Range` and `Scroll`.

### What my steps

**First**  
I Used `Range` And `Scroll` search the first 10000 size data

```auto
GET logstash-2018.01.22/_search?scroll=1m
{
    "query": {
        "bool": {
            "must": [{
                "range": {
                    "time_iso8601": {
                        "gte": 1516636800000,
                        "lte": 1516658400000,
                        "format": "epoch_millis"
                    }
                }
            }]
        }
    },
    "size": 10000
}

```

And i got the data:

```auto
{
    "_scroll_id": "DnF1ZXJ5VGhlbkZldGNoBQAAAAAAZtkCFmdORS1zNU9RVExxOVZ6VGJKTEtBcFEAAAAAAJdFnxZFeVVudDVaM1RJLW9pUWI4WkpQR3BRAAAAAABm2QMWZ05FLXM1T1FUTHE5VnpUYkpMS0FwUQAAAAAAE7BuFnQ2aFh2aVBQVDlpR3dSc1ppa1Uza2cAAAAAAJdFoBZFeVVudDVaM1RJLW9pUWI4WkpQR3BR",
    "took": 3354,
    "timed_out": false,
    "_shards": {
      "total": 5,
      "successful": 5,
      "failed": 0
    },
    "hits": {
      "total": 506943,
      "max_score": 1,
      "hits": [
        {
          "_index": "logstash-2018.01.22",
          "_type": "logs",
          "_id": "AWEe4DVE5NOBHBeKKltZ"
        }]
    }
    ................................
    ................................
    ................................
    ................................
    ................................
    ................................
}

```

**Second**  
Use `scroll_id` to search

```auto
GET /_search/scroll
{
    "scroll": "1m",
    "scroll_id": "{DnF1ZXJ5VGhlbkZldGNoBQAAAAAAZtkCFmdORS1zNU9RVExxOVZ6VGJKTEtBcFEAAAAAAJdFnxZFeVVudDVaM1RJLW9pUWI4WkpQR3BRAAAAAABm2QMWZ05FLXM1T1FUTHE5VnpUYkpMS0FwUQAAAAAAE7BuFnQ2aFh2aVBQVDlpR3dSc1ppa1Uza2cAAAAAAJdFoBZFeVVudDVaM1RJLW9pUWI4WkpQR3BR}"
}

```

And i got the data:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "illegal_argument_exception",
        "reason": "Cannot parse scroll id"
      }
    ],
    "type": "illegal_argument_exception",
    "reason": "Cannot parse scroll id",
    "caused_by": {
      "type": "illegal_argument_exception",
      "reason": "Illegal base64 character 7b"
    }
  },
  "status": 400
}

```

I don't know if it is a question of my operation. I saw a passage on this page: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-scroll.html:](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-scroll.html:)

```auto
If the request specifies aggregations, only the initial search response will contain the aggregations results.

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 27, 2018, 12:13pm UTC](https://discuss.elastic.co/t/about-aggregations-request-with-scroll-only-the-first-results-can-be-output/117300/2 "2018-01-27T12:13:05Z")

</div>

It's not a bug IMHO.

It'd be useless when you want to extract million of records to compute again and again the aggregations as you already got the result once when you started the extraction.

---

<div class="post-metadata">

**Author:** ![Pelin\_li](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pelin_li/32/27026_2.png) [@Pelin\_li](https://discuss.elastic.co/u/Pelin_li)\
**Post date:** [January 27, 2018, 12:21pm UTC](https://discuss.elastic.co/t/about-aggregations-request-with-scroll-only-the-first-results-can-be-output/117300/3 "2018-01-27T12:21:58Z")

</div>

Thanks for your reply.

I sorry that i'm not very understanding of the meaning. It means that after the first search with `range`, i can't use `scroll_id` continue to the next 10000 size of data?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 27, 2018, 1:20pm UTC](https://discuss.elastic.co/t/about-aggregations-request-with-scroll-only-the-first-results-can-be-output/117300/4 "2018-01-27T13:20:02Z")

</div>

Sorry. I misread and was confused by the title which does not reflect the question.

Anyway this should be:

```
GET /_search/scroll
{
   "scroll": "1m",
   "scroll_id": "DnF1ZXJ5VGhlbkZldGNoBQAAAAAAZtkCFmdORS1zNU9RVExxOVZ6VGJKTEtBcFEAAAAAAJdFnxZFeVVudDVaM1RJLW9pUWI4WkpQR3BRAAAAAABm2QMWZ05FLXM1T1FUTHE5VnpUYkpMS0FwUQAAAAAAE7BuFnQ2aFh2aVBQVDlpR3dSc1ppa1Uza2cAAAAAAJdFoBZFeVVudDVaM1RJLW9pUWI4WkpQR3BR"
}
```

---

<div class="post-metadata">

**Author:** ![Pelin\_li](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pelin_li/32/27026_2.png) [@Pelin\_li](https://discuss.elastic.co/u/Pelin_li)\
**Post date:** [January 27, 2018, 1:30pm UTC](https://discuss.elastic.co/t/about-aggregations-request-with-scroll-only-the-first-results-can-be-output/117300/5 "2018-01-27T13:30:14Z")

</div>

Oh, i'm very sorry. I do the wrong search, my search `/_search/scroll` with `scroll_id` has extra `{` and `}`

I'm sorry again about my carelessness. And thanks for your patient!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2018, 1:30pm UTC](https://discuss.elastic.co/t/about-aggregations-request-with-scroll-only-the-first-results-can-be-output/117300/6 "2018-02-24T13:30:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
