# Aggregation Sum is very slow

**URL:** <https://discuss.elastic.co/t/aggregation-sum-is-very-slow/148045>\
**Category:** Elasticsearch\
**Created:** [September 11, 2018, 5:17am UTC](https://discuss.elastic.co/t/aggregation-sum-is-very-slow/148045 "2018-09-11T05:17:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bruce88](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bruce88](https://discuss.elastic.co/u/bruce88)\
**Post date:** [September 11, 2018, 5:17am UTC](https://discuss.elastic.co/t/aggregation-sum-is-very-slow/148045/1 "2018-09-11T05:17:09Z")

</div>

I have a search on our ES cluster, which has 4 TB, 43 billion docs.

```
{
"query": {
    "bool": {
        "filter": [
            {
                "term": {
                    "CustomerID": {
                        "value": "s1501"
                    }
                }
            },
            {
                "range": {
                    "Timestamp": {
                        "from": 1533225600,
                        "to": 1535903998
                    }
                }
            }
        ]
    }
},
"aggregations": {
    "UserName": {
        "filter": {
            "bool": {
                "must_not": [
                    {
                        "terms": {
                            "UserName": [
                                ""
                            ]
                        }
                    }
                ]
            }
        },
        "aggregations": {
            "UserName": {
                "terms": {
                    "field": "UserName",
                    "size": 10,
                    "shard_size": 200
                },
                "aggregations": {
                    "total": {
                        "sum": {
                            "field": "InByte"
                        }
                    }
                }
            }
        }
    }
}

```

}

The search takes more than 10 seconds, but if I remove SUM and only use terms, it only takes about 1 seconds.  
Why the SUM takes so much time? Is there any ways to optimize?

BTW, only about 280,000 docs are matched in the search.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2018, 5:17am UTC](https://discuss.elastic.co/t/aggregation-sum-is-very-slow/148045/2 "2018-10-09T05:17:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
