# Aggregation & max value from doc\_count

**URL:** <https://discuss.elastic.co/t/aggregation-max-value-from-doc-count/250376>\
**Category:** Elasticsearch\
**Created:** [September 29, 2020, 2:26pm UTC](https://discuss.elastic.co/t/aggregation-max-value-from-doc-count/250376 "2020-09-29T14:26:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![KRISHNAPRASAD\_HG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishnaprasad_hg/32/76381_2.png) [@KRISHNAPRASAD\_HG](https://discuss.elastic.co/u/KRISHNAPRASAD_HG)\
**Post date:** [September 29, 2020, 2:26pm UTC](https://discuss.elastic.co/t/aggregation-max-value-from-doc-count/250376/1 "2020-09-29T14:26:38Z")

</div>

Hello,  
Hello,  
I need help for aggregation query.

Query :  
GET index-\*/\_search  
{  
"aggs": {  
"genres": {  
"terms": {  
"field": "COMPONENT\_NAME",  
"min\_doc\_count": 5  
}  
}  
},  
"query": {  
"bool": {  
"filter": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-3h"  
}  
}  
},  
{  
"match": {  
"LOG\_LEVEL": "ERROR"  
}  
}  
]  
}  
}  
}

Result:  
{  
"took" : 35,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 2,  
"successful" : 2,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : {  
"value" : 2,  
"relation" : "eq"  
},  
"max\_score" : 0.0,

},  
"aggregations" : {  
"genres" : {  
"doc\_count\_error\_upper\_bound" : 0,  
"sum\_other\_doc\_count" : 0,  
"buckets" : [  
{  
"key" : "ABC",  
"doc\_count" : 30  
},  
{  
"key" : "XYZ",  
"doc\_count" : 6  
}  
]  
}  
}  
}

Question : How i can get max document count in watcher compare section? "ctx.aggregations.genres.buckets.doc\_count[0].value" is not working.  
wrt above result "doc\_count" : 30 i want to compare.

"compare": {  
"ctx.aggregations.genres.buckets.doc\_count[0].value": {  
"gt": 5  
}  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 30, 2020, 9:28am UTC](https://discuss.elastic.co/t/aggregation-max-value-from-doc-count/250376/2 "2020-09-30T09:28:02Z")

</div>

please take your time and properly format your messages using markdown, this is really hard to read and markdown has excellent support for code snippets.

You need to use a [script condition](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/condition-script.html) instead. Then the first bucket can be accessed via `ctx.payload.aggregations.genres.buckets[0].doc_count`.

---

<div class="post-metadata">

**Author:** ![KRISHNAPRASAD\_HG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishnaprasad_hg/32/76381_2.png) [@KRISHNAPRASAD\_HG](https://discuss.elastic.co/u/KRISHNAPRASAD_HG)\
**Post date:** [October 2, 2020, 2:04pm UTC](https://discuss.elastic.co/t/aggregation-max-value-from-doc-count/250376/3 "2020-10-02T14:04:10Z")

</div>

Thanks a lot Alexander.

"ctx.payload.aggregations.genres.buckets.0.doc\_count"

is worked out me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 30, 2020, 2:04pm UTC](https://discuss.elastic.co/t/aggregation-max-value-from-doc-count/250376/4 "2020-10-30T14:04:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
