# Aggregate over an array

**URL:** <https://discuss.elastic.co/t/aggregate-over-an-array/49716>\
**Category:** Kibana\
**Created:** [May 11, 2016, 1:41am UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716 "2016-05-11T01:41:48Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rcompton](https://avatars.discourse-cdn.com/v4/letter/r/8491ac/32.png) [@rcompton](https://discuss.elastic.co/u/rcompton)\
**Post date:** [May 11, 2016, 1:41am UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716/1 "2016-05-11T01:41:48Z")

</div>

I have an array field,

```auto
strArray: ['browser:IE', 'device:PC', 'country:USA', 'state:CA']

```

I'd like to draw a bar chart in kibana showing the most common entries in position 0 of that field.

I'm entering into the Advanced JSON input :

```auto
{
   "terms": {
       "script": "doc['strArray']"
    }
}

```

but my queries fail. What am I missing?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [May 11, 2016, 6:23pm UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716/2 "2016-05-11T18:23:23Z")

</div>

As far as I know, Elasticsearch doesn't provide a way to do an aggregations on a position in the array, just on all the values it finds. Internally, I don't think Elasticsearch keeps track of the order of the items at all, so there's not even a way to make this work.

Your best bet is, if you know that the position of the values in that array have an important meaning, is to simply index that value in a new field along side that `strArray` field.

---

<div class="post-metadata">

**Author:** ![rcompton](https://avatars.discourse-cdn.com/v4/letter/r/8491ac/32.png) [@rcompton](https://discuss.elastic.co/u/rcompton)\
**Post date:** [May 11, 2016, 6:28pm UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716/3 "2016-05-11T18:28:30Z")

</div>

Interesting. Is there no notion of position for arrays in ES or is it just not a built in aggregation?

Would it be possible to write a (groovy?) script that somehow gets around this?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 11, 2016, 9:33pm UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716/4 "2016-05-11T21:33:52Z")

</div>

You could probably do a scripted agg for this.

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [May 11, 2016, 9:53pm UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716/5 "2016-05-11T21:53:59Z")

</div>

I'm not well versed in groovy scripting in ES, but you might be able to do this via a scripted field. [Here's the docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-scripting.html) if you want to give it a go. Be aware that you have to manually enable groovy scripting in your configuration.

I was told that Elasticsearch doesn't ensure the order of arrays though, so it's possible this may not work either. I may have been told wrong though, asking about it over on the elasticsearch boards would probably get you better answers.

---

<div class="post-metadata">

**Author:** ![rcompton](https://avatars.discourse-cdn.com/v4/letter/r/8491ac/32.png) [@rcompton](https://discuss.elastic.co/u/rcompton)\
**Post date:** [May 12, 2016, 4:39pm UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716/6 "2016-05-12T16:39:09Z")

</div>

scripted aggs are possible in kibana, right?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [May 12, 2016, 7:45pm UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716/7 "2016-05-12T19:45:34Z")

</div>

We support scripted fields using the Lucene Query Syntax out of the box. If you want to use groovy scripts, you'll need to enable them in elasticsearch first (be aware that there are security implications).

You can use scripted aggs should work too, using the JSON input and crafting your query by hand that way.

---

<div class="post-metadata">

**Author:** ![rcompton](https://avatars.discourse-cdn.com/v4/letter/r/8491ac/32.png) [@rcompton](https://discuss.elastic.co/u/rcompton)\
**Post date:** [May 12, 2016, 7:50pm UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716/8 "2016-05-12T19:50:27Z")

</div>

> [@Joe\_Fleming](#):
>
> You can use scripted aggs should work too, using the JSON input and crafting your query by hand that way.

Is there an example of scripted aggs somewhere?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [May 12, 2016, 8:38pm UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716/9 "2016-05-12T20:38:03Z")

</div>

I actually don't know about any examples. There are probably some examples on the Internet somewhere if you go look for them though.

If you're asking about [scripted metric aggs](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-scripted-metric-aggregation.html), I don't think they are possible in Kibana. The JSON input simply lets you add additional parameters to the existing aggregation, and we don't offer scripted metrics as an option.

You might be able to do what you're trying to do with scripted fields though. Scripted fields are different, they are added as fields to your index pattern. Out of the box, the are limited to the Lucene syntax, which only supports numbers. But, if you enable groovy scripting, you can give you field a custom script `type`. See the [script fields](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-script-fields.html), [scripts in terms aggs](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-script) and [scripting](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-scripting.html) docs to get started.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:53pm UTC](https://discuss.elastic.co/t/aggregate-over-an-array/49716/10 "2017-07-06T13:53:30Z")

</div>


